PT-2003-1884 · Quagga+1 · Quagga+1

Jonny Robertson

·

Publicado

2003-11-18

·

Atualizado

2016-10-18

·

CVE-2003-0795

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Quagga versions prior to 0.96.4 Zebra versions prior to 0.93b
Description: The issue allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference. This occurs because the vty layer does not verify that sub-negotiation is taking place when processing the SE marker.
Recommendations: For Quagga versions prior to 0.96.4, update to version 0.96.4 or later to resolve the issue. For Zebra versions prior to 0.93b, update to version 0.93b or later to resolve the issue. As a temporary workaround, consider restricting access to the telnet CLI port until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-0795

Produtos afetados

Quagga
Zebra