Beschreibung: | Description:
The remote host is missing updates announced in advisory CLA-2004:845.
The Linux kernel is responsible for handling the basic functions of the GNU/Linux operating system.
This announcement fixes the following vulnerabilities:
1. Local denial of service vulnerability (CVE-2004-0554[1])
Stian Skjelstad found[2] a vulnerability[1] in the fpu controller code that can be used by local attackers to cause a denial of service (DoS) on the system.
2. Local memory disclosure vulnerability (CVE-2004-0535[3])
Chris Wright found a vulnerability[3] in the Intel(R) PRO/1000 ethernet card driver that could allow a local attacker to read some bytes of kernel memory.
3. Sparse vulnerabilities (CVE-2004-0495[4])
Al Viro, by using Sparse[5] (a code inspection tool), found several vulnerabilities which, in the worst case, might allow local attackers to obtain root privileges.
Solution: The apt tool can be used to perform RPM package upgrades by running 'apt-get update' followed by 'apt-get upgrade'
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0554 http://marc.theaimsgroup.com/?l=linux-kernel&m=108681568931323&w=2 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0535 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0495 http://sparse.bkbits.net:8080/sparse/ http://www.conectiva.com.br/suporte/pr/sistema.kernel.atualizar.html http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:845 http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004
Risk factor : High
CVSS Score: 7.2
|