DSA-415

    Dashboard / Vulnerabilities / DSA-415

    DSA-415

    Published: 6 Jan 2004Last Modified: 4 Jul 2022

    Summary: zebra - denial of service

    Details: Two vulnerabilities were discovered in zebra, an IP routing daemon: * [CAN-2003-0795](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0795) - a bug in the telnet CLI could allow a remote attacker to cause a zebra process to crash, resulting in a denial of service. * [CAN-2003-0858](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0858) - netlink messages sent by other users (rather than the kernel) would be accepted, leading to a denial of service. For the current stable distribution (woody) this problem has been fixed in version 0.92a-5woody2. The zebra package has been obsoleted in the unstable distribution by GNU Quagga, where this problem was fixed in version 0.96.4x-4. We recommend that you update your zebra package.

    References:

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High