Descripción: | Description:
The remote host is missing updates announced in advisory TSLSA-2006-0028.
kernel < TSL 3.0 > - New Upstream. - SECURITY Fix: Memory leak in __setlease in fs/locks.c allows attackers to cause a denial of service (memory consumption) via unspecified actions related to an uninitialised return value, aka slab leak. - lease_init in fs/locks.c allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2006-1859 and CVE-2006-1860 to these issue.
mysql < TSL 3.0 > < TSL 2.2 > < TSEL 2 > - SECURITY Fix: Stefano Di Paola has reported some vulnerabilities in MySQL, which can be exploited by malicious users to disclose potentially sensitive information and compromise a vulnerable system. - The check_connection function in sql_parse.cc in MySQL allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read. - sql_parse.cc in MySQL allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2006-1516 and CVE-2006-1517 to these issues.
Solution: Update your system with the packages as indicated in the referenced security advisory.
http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2006-0028
Risk factor : Medium
CVSS Score: 5.0
|