[ MDVSA-2008:086 ] - Updated kernel packages fix vulnerabili

Mandrivan turvallisuustiedotteiden tuoreimmat

[ MDVSA-2008:086 ] - Updated kernel packages fix vulnerabili

Uusi viestiKirjoittaja dude67 » 16 Huhti 2008, 11:41

Updated kernel packages fix vulnerability

The isdn_ioctl function in isdn_common.c in the Linux kernel prior to
2.6.23 allows local users to cause a denial of service via a crafted
ioctl struct in which iocts is not null terminated, which trigger a
buffer overflow (CVE-2007-6151).

The do_corefump function in fs/exec.c in the Linux kernel prior to
2.6.24-rc3 did not change the UID of a core dump file if it exists
before a root process creates a core dump in the same location, which
could possibly allow local users to obtain sensitive information
(CVE-2007-6206).

The shmem_getpage function in mm/shmem.c in the Linux kernel versions
2.6.11 through 2.6.23 did not properly clear allocated memory in
certain rare circumstances related to tmps, which could possibly
allow local users to read sensitive kernel data or cause a crash
(CVE-2007-6417).

Additionally, this kernel provides a fix for megaraid_sas and updates
it to version 3.13, updates mptsas to version 3.12.19, and updates
e1000-ng to version 7.6.12, as well as adds igb version 1.0.8.

To update your kernel, please follow the directions located at:

http://www.mandriva.com/en/security/kernelupdate
Kuva
1. Mageia-1 KDE4 x86_64 (& Win7 Pro) | desktop
2. Mageia-2 KDE4 (& Win7 Home Premium) | laptop Acer 7530
3. Mageia-1 KDE4 (& Win7 Starter) | Samsung NC-10 miniläppäri
4. Mageia-1 KDE4 | serverinä toimiva desktop
Luotettavaa Linux käyttöä jo Mandriva 2006.0:sta lähtien :)
Avatar
dude67
Site Admin
 
Viestit: 2256
Liittynyt: 27 Syys 2007, 16:58
Paikkakunta: Espoo

Paluu Mandrivan turvallisuustiedotteet

Paikallaolijat

Käyttäjiä lukemassa tätä aluetta: Ei rekisteröityneitä käyttäjiä ja 42 vierailijaa

cron