Back

HIGH

zaptel: Array index error in tor2 zaptel driver (incomplete fix for CVE-2008-5396)

Published Dec 26, 2008

Description

Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incorrect tor2 patch for CVE-2008-5396 that uses the wrong variable in a range check against the value of lc->sync.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 26, 2008
Updated Aug 7, 2024
Reserved Dec 26, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Dec 19, 2008