VYPR
Unrated severityNVD Advisory· Published Dec 15, 2003· Updated Apr 16, 2026

CVE-2003-0795

CVE-2003-0795

Description

The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.

Affected products

11
  • GNU/Zebra4 versions
    cpe:2.3:a:gnu:zebra:0.91a:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:gnu:zebra:0.91a:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:zebra:0.92a:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:zebra:0.93a:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:zebra:0.93b:*:*:*:*:*:*:*
  • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*range: <=0.96.3
    • cpe:2.3:a:quagga:quagga:0.95:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.1:*:*:*:*:*:*:*
    • cpe:2.3:a:quagga:quagga:0.96.2:*:*:*:*:*:*:*
  • Sgi/Propack2 versions
    cpe:2.3:a:sgi:propack:2.2.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sgi:propack:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:sgi:propack:2.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.