Lucene search

K
redhatRedHatRHSA-2003:305
HistoryNov 12, 2003 - 12:00 a.m.

(RHSA-2003:305) zebra security update

2003-11-1200:00:00
access.redhat.com
10

0.018 Low

EPSS

Percentile

88.1%

Zebra an open source implementation of TCP/IP routing software.

Jonny Robertson reported that Zebra can be remotely crashed if a Zebra
password has been enabled and a remote attacker can connect to the Zebra
telnet management port. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0795 to this issue.

Herbert Xu reported that Zebra can accept spoofed messages sent on the
kernel netlink interface by other users on the local machine. This could
lead to a local denial of service attack. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2003-0858 to
this issue.

Users of Zebra should upgrade to these erratum packages, which contain
a patch preventing Zebra from crashing when it receives a telnet option
delimiter without any option data, and a patch that checks that netlink
messages actually came from the kernel.

OSVersionArchitecturePackageVersionFilename
RedHatanyia64zebra< 0.91a-10.21ASzebra-0.91a-10.21AS.ia64.rpm
RedHatanyi386zebra< 0.91a-10.21ASzebra-0.91a-10.21AS.i386.rpm