Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.53944
Kategorie:Slackware Local Security Checks
Titel:Slackware: Security Advisory (SSA:2004-049-01)
Zusammenfassung:The remote host is missing an update for the 'Kernel' package(s) announced via the SSA:2004-049-01 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'Kernel' package(s) announced via the SSA:2004-049-01 advisory.

Vulnerability Insight:
New kernels are available for Slackware 9.1 and -current to fix
a bounds-checking problem in the kernel's mremap() call which
could be used by a local attacker to gain root privileges.
Please note that this is not the same issue as CAN-2003-0985
which was fixed in early January.

The kernels in Slackware 8.1 and 9.0 that were updated in
January are not vulnerable to this new issue because the patch
from Solar Designer that was used to fix the CAN-2003-0985 bugs
also happened to fix the problem that was discovered later.

Sites running Slackware 9.1 or -current should upgrade to a
new kernel. After installing the new kernel, be sure to run
'lilo'.

More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:

[link moved to references]


Here are the details from the Slackware 9.1 ChangeLog:
+--------------------------+
Wed Feb 18 03:44:42 PST 2004
patches/kernels/: Recompiled to fix another bounds-checking error in
the kernel mremap() code. (this is not the same issue that was fixed
on Jan 6) This bug could be used by a local attacker to gain root
privileges. Sites should upgrade to a new kernel. After installing
the new kernel, be sure to run 'lilo'.
For more details, see:
[link moved to references]
Thanks to Paul Starzetz for finding and researching this issue.
(* Security fix *)
patches/packages/kernel-ide-2.4.24-i486-2.tgz: Patched, recompiled.
(* Security fix *)
patches/packages/kernel-source-2.4.24-noarch-2.tgz: Patched the kernel
source with a fix for the mremap() problem from Solar Designer, and
updated the Speakup driver (not pre-applied).
(* Security fix *)
+--------------------------+

Affected Software/OS:
'Kernel' package(s) on Slackware 9.1, Slackware current.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2003-0985
BugTraq ID: 9356
http://www.securityfocus.com/bid/9356
Bugtraq: 20040105 Linux kernel do_mremap() proof-of-concept exploit code (Google Search)
http://marc.info/?l=bugtraq&m=107340358402129&w=2
Bugtraq: 20040105 Linux kernel mremap vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=107332782121916&w=2
Bugtraq: 20040106 Linux mremap bug correction (Google Search)
http://marc.info/?l=bugtraq&m=107340814409017&w=2
Bugtraq: 20040107 [slackware-security] Kernel security update (SSA:2004-006-01) (Google Search)
http://marc.info/?l=bugtraq&m=107350348418373&w=2
Bugtraq: 20040108 [slackware-security] Slackware 8.1 kernel security update (SSA:2004-008-01) (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2004-01/0070.html
Bugtraq: 20040112 SmoothWall Project Security Advisory SWP-2004:001 (Google Search)
http://marc.info/?l=bugtraq&m=107394143105081&w=2
CERT/CC vulnerability note: VU#490620
http://www.kb.cert.org/vuls/id/490620
Computer Incident Advisory Center Bulletin: O-045
http://www.ciac.org/ciac/bulletins/o-045.shtml
Conectiva Linux advisory: CLA-2004:799
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000799
Debian Security Information: DSA-1067 (Google Search)
http://www.debian.org/security/2006/dsa-1067
Debian Security Information: DSA-1069 (Google Search)
http://www.debian.org/security/2006/dsa-1069
Debian Security Information: DSA-1070 (Google Search)
http://www.debian.org/security/2006/dsa-1070
Debian Security Information: DSA-1082 (Google Search)
http://www.debian.org/security/2006/dsa-1082
Debian Security Information: DSA-413 (Google Search)
http://www.debian.org/security/2004/dsa-413
Debian Security Information: DSA-417 (Google Search)
http://www.debian.org/security/2004/dsa-417
Debian Security Information: DSA-423 (Google Search)
http://www.debian.org/security/2004/dsa-423
Debian Security Information: DSA-427 (Google Search)
http://www.debian.org/security/2004/dsa-427
Debian Security Information: DSA-439 (Google Search)
http://www.debian.org/security/2004/dsa-439
Debian Security Information: DSA-440 (Google Search)
http://www.debian.org/security/2004/dsa-440
Debian Security Information: DSA-442 (Google Search)
http://www.debian.org/security/2004/dsa-442
Debian Security Information: DSA-450 (Google Search)
http://www.debian.org/security/2004/dsa-450
Debian Security Information: DSA-470 (Google Search)
http://www.debian.org/security/2004/dsa-470
Debian Security Information: DSA-475 (Google Search)
http://www.debian.org/security/2004/dsa-475
En Garde Linux Advisory: ESA-20040105-001
http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html
Immunix Linux Advisory: IMNX-2004-73-001-01
http://download.immunix.org/ImmunixOS/7.3/updates/IMNX-2004-73-001-01
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:001
http://isec.pl/vulnerabilities/isec-0013-mremap.txt
http://www.osvdb.org/3315
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A860
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A867
http://www.redhat.com/support/errata/RHSA-2003-416.html
http://www.redhat.com/support/errata/RHSA-2003-417.html
http://www.redhat.com/support/errata/RHSA-2003-418.html
http://www.redhat.com/support/errata/RHSA-2003-419.html
http://secunia.com/advisories/10532
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
SGI Security Advisory: 20040102-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040102-01-U
SuSE Security Announcement: SuSE-SA:2004:001 (Google Search)
SuSE Security Announcement: SuSE-SA:2004:003 (Google Search)
http://www.novell.com/linux/security/advisories/2004_03_linux_kernel.html
http://marc.info/?l=bugtraq&m=107332754521495&w=2
XForce ISS Database: linux-domremap-gain-privileges(14135)
https://exchange.xforce.ibmcloud.com/vulnerabilities/14135
Common Vulnerability Exposure (CVE) ID: CVE-2004-0077
BugTraq ID: 9686
http://www.securityfocus.com/bid/9686
Bugtraq: 20040218 Second critical mremap() bug found in all Linux kernels (Google Search)
http://marc.info/?l=bugtraq&m=107711762014175&w=2
CERT/CC vulnerability note: VU#981222
http://www.kb.cert.org/vuls/id/981222
Computer Incident Advisory Center Bulletin: O-082
http://www.ciac.org/ciac/bulletins/o-082.shtml
Conectiva Linux advisory: CLA-2004:820
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000820
Debian Security Information: DSA-438 (Google Search)
http://www.debian.org/security/2004/dsa-438
Debian Security Information: DSA-441 (Google Search)
http://www.debian.org/security/2004/dsa-441
Debian Security Information: DSA-444 (Google Search)
http://www.debian.org/security/2004/dsa-444
Debian Security Information: DSA-453 (Google Search)
http://www.debian.org/security/2004/dsa-453
Debian Security Information: DSA-454 (Google Search)
http://www.debian.org/security/2004/dsa-454
Debian Security Information: DSA-456 (Google Search)
http://www.debian.org/security/2004/dsa-456
Debian Security Information: DSA-466 (Google Search)
http://www.debian.org/security/2004/dsa-466
Debian Security Information: DSA-514 (Google Search)
http://www.debian.org/security/2004/dsa-514
http://fedoranews.org/updates/FEDORA-2004-079.shtml
http://security.gentoo.org/glsa/glsa-200403-02.xml
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015
http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt
http://www.osvdb.org/3986
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A825
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A837
http://www.redhat.com/support/errata/RHSA-2004-065.html
http://www.redhat.com/support/errata/RHSA-2004-066.html
http://www.redhat.com/support/errata/RHSA-2004-069.html
http://www.redhat.com/support/errata/RHSA-2004-106.html
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.404734
SuSE Security Announcement: SuSE-SA:2004:005 (Google Search)
http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html
http://marc.info/?l=bugtraq&m=107712137732553&w=2
http://marc.info/?l=bugtraq&m=107755871932680&w=2
TurboLinux Advisory: TLSA-2004-7
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0040.html
XForce ISS Database: linux-mremap-gain-privileges(15244)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15244
CopyrightCopyright (C) 2012 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.