Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2020.0355
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2020-0355)
Zusammenfassung:The remote host is missing an update for the 'kernel, kernel-linus, kmod-virtualbox, kmod-xtables-addons, wireguard-tools' package(s) announced via the MGASA-2020-0355 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'kernel, kernel-linus, kmod-virtualbox, kmod-xtables-addons, wireguard-tools' package(s) announced via the MGASA-2020-0355 advisory.

Vulnerability Insight:
This update is based on the upstream 5.7.19 kernel and fixes at least the
following security issue:

In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem
image, performing some operations, and then making a syncfs system call can
lead to a use-after-free in try_merge_free_space in
fs/btrfs/free-space-cache.c because the pointer to a left data structure can
be the same as the pointer to a right data structure (CVE-2019-19448).

A memory out-of-bounds read flaw was found in the Linux kernel's ext3/ext4
filesystem, in the way it accesses a directory with broken indexing. This flaw
allows a local user to crash the system if the directory exists. The highest
threat from this vulnerability is to system availability (CVE-2020-14314).

For other upstream fixes and changes in this update, see the referenced
changelogs.

Also, the wireguard-tools package has been updated to version 1.0.20200827.

Affected Software/OS:
'kernel, kernel-linus, kmod-virtualbox, kmod-xtables-addons, wireguard-tools' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-19448
https://github.com/bobfuzzer/CVE/tree/master/CVE-2019-19448
https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html
https://usn.ubuntu.com/4578-1/
Common Vulnerability Exposure (CVE) ID: CVE-2020-14314
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14314
https://www.starwindsoftware.com/security/sw-20210325-0003/
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5872331b3d91820e14716632ebb56b1399b34fe1
https://lore.kernel.org/linux-ext4/f53e246b-647c-64bb-16ec-135383c70ad7@redhat.com/T/#u
https://usn.ubuntu.com/4576-1/
https://usn.ubuntu.com/4579-1/
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.