CVE-2003-0795
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.
Scoring
- CVSS base score
- 0.32
- EPSS probability
- 8.01%
- Published
- 2003-11-18
- Last modified
- 2026-03-16
Affected products
- n/a n/a