--------------------------------------------------------------------------
Turbolinux Security Advisory TLSA-2002-41
http://www/turbolinux.co.jp/security/
security-team@turbolinux.co.jp
--------------------------------------------------------------------------
Kernel
Vulnerability of file descriptor
Release date : 2002-07-13
Solution: package : kernel-2.4.18-3
Problem
Problem exists in the local user file descriptor.
Solution:
Please verify version and execute the command below.
# rpm -qa | grep package name
When problem corresponds, please download the update package. Do the update by the using the command below.
Furthermore, please execute the package number which corresponds to your version number. Without starting a new paragraph, please enter the "\ " Bunchu sign.
Execution example
---------------------------------------------------------------------
# rpm -Fvh Package-1.0.0-1.i586.rpm \
Package-doc-1.0.0-1.i586.rpm \
Package-devel-1.0.0-1.i586.rpm
The case where rpm command is executed, please enter as follows on the command line.
# rpm -Fvh package-1.0.0-1.i586.rpm package-doc-1.0.0-1.i586.rpm package-devel-1.0.0-1.i586.rpm
---------------------------------------------------------------------
< Turbolinux 8 Workstation >
< Turbolinux 7 Server >
< Turbolinux 7 Workstation >
# rpm -Fvh kernel-2.4.18-3.i586.rpm \
kernel-BOOT-2.4.18-3.i586.rpm \
kernel-doc-2.4.18-3.i586.rpm \
kernel-headers-2.4.18-3.i586.rpm \
kernel-pcmcia-cs-2.4.18-3.i586.rpm \
kernel-smp-2.4.18-3.i586.rpm \
kernel-smp64g-2.4.18-3.i586.rpm \
kernel-source-2.4.18-3.i586.rpm
* Note
* After the updating it is necessary to restart the system.
* When updating from previous versio kernel-2.4.18,
It is also necessary for the below-mentioned package to update simultaneously.
e2fsprogs-1.25-2
e2fsprogs-devel-1.25-2
iptables-1.2.5-2
iptables-ipv6-1.2.5-2
jfsutils-1.0.17-1
quota-3.01-5
reiserfsprogs-3.x.0j-2
< Turbolinux Server 6.5 >
< Turbolinux Advanced Server 6 >
< Turbolinux Server 6.1 >
< Turbolinux Workstation 6.0 >
* This case is problem of kernel 2.4 type.
In the product which uses kernel 2.2 system it is not necessary to update.
Package updates:
http://www.turbolinux.co.jp/update/