Red Hat Bugzilla – Bug 155365
CVE-2005-3273 ROSE ndigis verification
Last modified: 2007-11-30 17:07:07 EST
An error exists in ROSE due to missing verification of the ndigis argument of new routes. This was found by Coverity 20041216, rose_rt_ioctl. http://linux.bkbits.net:8080/linux-2.6/cset@423114bcdthRtmtdS6MsZiBVvteGCg http://linux.bkbits.net:8080/linux-2.4/cset@41e2cf515TpixcVQ8q8HvQvCv9E6zA
Note that this module is in kernel-unsupported for RHEL3
A fix for this problem has just been committed to the RHEL3 U6 patch pool this evening (in kernel version 2.4.21-32.6.EL).
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-663.html