Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.13.2016.347.01
Kategorie:Slackware Local Security Checks
Titel:Slackware: Security Advisory (SSA:2016-347-01)
Zusammenfassung:The remote host is missing an update for the 'kernel' package(s) announced via the SSA:2016-347-01 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'kernel' package(s) announced via the SSA:2016-347-01 advisory.

Vulnerability Insight:
New kernel packages are available for Slackware 14.2 and -current to
fix a security issue.


Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packages/linux-4.4.38/*: Upgraded.
This kernel fixes a security issue with a race condition in
net/packet/af_packet.c that can be exploited to gain kernel code execution
from unprivileged processes.
Thanks to Philip Pettersson for discovering the bug and providing a patch.
Be sure to upgrade your initrd after upgrading the kernel packages.
If you use lilo to boot your machine, be sure lilo.conf points to the correct
kernel and initrd and run lilo as root to update the bootloader.
If you use elilo to boot your machine, you should run eliloconfig to copy the
kernel and initrd to the EFI System Partition.
For more information, see:
[links moved to references]
(* Security fix *)
+--------------------------+

Affected Software/OS:
'kernel' package(s) on Slackware 14.2, Slackware current.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-8655
1037403
http://www.securitytracker.com/id/1037403
1037968
http://www.securitytracker.com/id/1037968
40871
https://www.exploit-db.com/exploits/40871/
44696
https://www.exploit-db.com/exploits/44696/
94692
http://www.securityfocus.com/bid/94692
RHSA-2017:0386
http://rhn.redhat.com/errata/RHSA-2017-0386.html
RHSA-2017:0387
http://rhn.redhat.com/errata/RHSA-2017-0387.html
RHSA-2017:0402
http://rhn.redhat.com/errata/RHSA-2017-0402.html
SUSE-SU-2016:3096
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00044.html
SUSE-SU-2016:3113
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00054.html
SUSE-SU-2016:3116
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00055.html
SUSE-SU-2016:3117
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00056.html
SUSE-SU-2016:3169
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00067.html
SUSE-SU-2016:3183
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00070.html
SUSE-SU-2016:3197
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00073.html
SUSE-SU-2016:3205
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00076.html
SUSE-SU-2016:3206
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00077.html
SUSE-SU-2016:3247
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00087.html
USN-3149-1
http://www.ubuntu.com/usn/USN-3149-1
USN-3149-2
http://www.ubuntu.com/usn/USN-3149-2
USN-3150-1
http://www.ubuntu.com/usn/USN-3150-1
USN-3150-2
http://www.ubuntu.com/usn/USN-3150-2
USN-3151-1
http://www.ubuntu.com/usn/USN-3151-1
USN-3151-2
http://www.ubuntu.com/usn/USN-3151-2
USN-3151-3
http://www.ubuntu.com/usn/USN-3151-3
USN-3151-4
http://www.ubuntu.com/usn/USN-3151-4
USN-3152-1
http://www.ubuntu.com/usn/USN-3152-1
USN-3152-2
http://www.ubuntu.com/usn/USN-3152-2
[oss-security] 20161206 CVE-2016-8655 Linux af_packet.c race condition (local root)
http://www.openwall.com/lists/oss-security/2016/12/06/1
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=84ac7260236a49c79eede91617700174c2c19b0c
http://packetstormsecurity.com/files/140063/Linux-Kernel-4.4.0-AF_PACKET-Race-Condition-Privilege-Escalation.html
https://bugzilla.redhat.com/show_bug.cgi?id=1400019
https://github.com/torvalds/linux/commit/84ac7260236a49c79eede91617700174c2c19b0c
https://source.android.com/security/bulletin/2017-03-01.html
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.