Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-3273
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3273

Description:
The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, does not properly verify the ndigis argument for a new route, which allows attackers to trigger array out-of-bounds errors with a large number of digipeats.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-219-1

ST
  1014115

SAID
  Secunia Advisory: SA21035
  Secunia Advisory: SA17826
  Secunia Advisory: SA18056

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0580.html
  http://www.redhat.com/support/errata/RHSA-2005-663.html
  http://www.redhat.com/support/errata/RHSA-2006-0579.html

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219

MANDRAKE
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:220
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:219
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:218

FEDORA
  http://www.securityfocus.com/archive/1/archive/1/428028/100/0/threaded

DEBIAN
  http://www.debian.org/security/2005/dsa-922

CONFIRM
  http://linux.bkbits.net:8080/linux-2.6/cset@423114bcdthRtmtdS6MsZiBVvteGCg
  http://lkml.org/lkml/2005/5/23/169
  http://linux.bkbits.net:8080/linux-2.4/cset@41e2cf515TpixcVQ8q8HvQvCv9E6zA

BID
  13886


Return to the previous page.