LWN.net Logo

zebra: denial of service vulnerability

Package(s):zebra CVE #(s):CAN-2003-0795 CAN-2003-0858
Created:November 13, 2003 Updated:January 7, 2004
Description: Zebra an open source implementation of TCP/IP routing software.

Jonny Robertson reported that Zebra can be remotely crashed if a Zebra password has been enabled and a remote attacker can connect to the Zebra telnet management port. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0795 to this issue.

Herbert Xu reported that Zebra can accept spoofed messages sent on the kernel netlink interface by other users on the local machine. This could lead to a local denial of service attack. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0858 to this issue.

Alerts:
Debian DSA-415-1 2004-01-06
OpenPKG OpenPKG-SA-2003.049 2003-11-25
Conectiva CLA-2003:786 2003-11-20
Red Hat RHSA-2003:307-01 2003-11-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds