Revision Date: | 2003-11-12 | Version: | 502 |
Title: | RHSA-2003:315: quagga security update (Low) |
Description: | Quagga is an open source implementation of TCP/IP routing software. Herbert Xu reported that Quagga can accept spoofed messages sent on the kernel netlink interface by other users on the local machine. This could lead to a local denial of service attack. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0858 to this issue. Users of Quagga should upgrade to these erratum packages, which contain a patch that checks that netlink messages actually came from the kernel. This erratum also includes quagga-devel and quagga-contrib packages which were not originally shipped with Red Hat Enterprise Linux 3.
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | CVE-2003-0858 RHSA-2003:315-01
|
Platform(s): | Red Hat Enterprise Linux 3
| Product(s): | |
Definition Synopsis |
Red Hat Enterprise Linux 3 is installed AND Package Information
quagga-devel is earlier than 0:0.96.2-8.3E
AND quagga-devel is signed with Red Hat master key
OR
quagga-contrib is earlier than 0:0.96.2-8.3E
AND quagga-contrib is signed with Red Hat master key
OR
quagga is earlier than 0:0.96.2-8.3E
AND quagga is signed with Red Hat master key
|