[ MDVSA-2008:246 ] kernel

Mandrivan turvallisuustiedotteiden tuoreimmat

[ MDVSA-2008:246 ] kernel

Uusi viestiKirjoittaja dude67 » 29 Joulu 2008, 20:58

Some vulnerabilities were discovered and corrected in the Linux
2.6 kernel:

The chip_command function in drivers/media/video/tvaudio.c in the
Linux kernel 2.6.25.x before 2.6.25.19, 2.6.26.x before 2.6.26.7,
and 2.6.27.x before 2.6.27.3 allows attackers to cause a denial of
service (NULL function pointer dereference and OOPS) via unknown
vectors. (CVE-2008-5033)

Stack-based buffer overflow in the hfs_cat_find_brec function
in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows
attackers to cause a denial of service (memory corruption or system
crash) via an hfs filesystem image with an invalid catalog namelength
field, a related issue to CVE-2008-4933. (CVE-2008-5025)

Additionally, added enhancements for a newer revision of Nokia models
6300, XpressMusic 5200, 5610 and 7610, the support for the ub USB
module was disabled, added fixes for the Wake On LAN feature of the
r8169 module, added fixes for suspend and resume on the i915 module,
added ALSA fixes for Intel HDA, added workaround for a bug on iwlagn,
added the m5602 driver, fixed a crash on the ppscsi module, added
fixes to the uvcvideo module.

To update your kernel, please follow the directions located at:

http://www.mandriva.com/en/security/kernelupdate
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-5033
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-5025
https://qa.mandriva.com/45599
https://qa.mandriva.com/41782
https://qa.mandriva.com/44988
https://qa.mandriva.com/44891
https://qa.mandriva.com/45393
_______________________________________________________________________
Kuva
1. Mageia-1 KDE4 x86_64 (& Win7 Pro) | desktop
2. Mageia-2 KDE4 (& Win7 Home Premium) | laptop Acer 7530
3. Mageia-1 KDE4 (& Win7 Starter) | Samsung NC-10 miniläppäri
4. Mageia-1 KDE4 | serverinä toimiva desktop
Luotettavaa Linux käyttöä jo Mandriva 2006.0:sta lähtien :)
Avatar
dude67
Site Admin
 
Viestit: 2256
Liittynyt: 27 Syys 2007, 16:58
Paikkakunta: Espoo

Paluu Mandrivan turvallisuustiedotteet

Paikallaolijat

Käyttäjiä lukemassa tätä aluetta: Ei rekisteröityneitä käyttäjiä ja 42 vierailijaa

cron