Jump to content

Security Advisories (MDKSA-2004:066): kernel


 Share

Recommended Posts

Mandrakesoft Security Advisories MDKSA-2004:066 : kernel

 

Updated kernel packages fix multiple vulnerabilities

July 6th, 2004

 

A number of vulnerabilities were discovered in the Linux kernel that are corrected with this update:

 

Multiple vulnerabilities were found by the Sparse source checker that could allow local users to elevate privileges or gain access to kernel memory (CAN-2004-0495).

 

Missing Discretionary Access Controls (DAC) checks in the chown(2) system call could allow an attacker with a local account to change the group ownership of arbitrary files, which could lead to root privileges on affected systems (CAN-2004-0497).

 

An information leak vulnerability that affects only ia64 systems was fixed (CAN-2004-0565).

 

Insecure permissions on /proc/scsi/qla2300/HbaApiNode could allow a local user to cause a DoS on the system; this only affectsMandrakelinux 9.2 and below (CAN-2004-0587).

 

A vulnerability that could crash the kernel has also been fixed.This crash, however, can only be exploited via root (in br_if.c).

 

The provided packages are patched to fix these vulnerabilities.All users are encouraged to upgrade to these updated kernels.

 

To update your kernel, please follow the directions located at:

 

http://www.mandrakesoft.com/security/kernelupdate

 

 

The released versions of Mandrake GNU/Linux affected are:

  • 9.1
  • 9.2
  • 10.0
  • MNF8.2
  • CS2.1

Full information about this advisory, including the updated packages, is available at:

www.mandrakesoft.com/security/advisories?name=MDKSA-2004:066

 

Other references:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0495

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0497

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0565

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0587

 

Posted automatically by aru (mdksec2mub v0.0.9)

Link to comment
Share on other sites

 Share

×
×
  • Create New...