Description: | Summary: The remote host is missing an update for the 'kernel, ocfs2-2.6.18-8.1.10.0.1.el5, oracleasm-2.6.18-8.1.10.0.1.el5' package(s) announced via the ELSA-2007-0705 advisory.
Vulnerability Insight: [2.6.18-8.1.10.0.1.el5] - Fix bonding primary=ethX (Bert Barbe) [IT 101532] [ORA 5136660] - Add entropy module option to e1000/bnx2 (John Sobecki) [ORA 6045759]
[2.6.18-8.1.10.el5] - [mm] Prevent the stack growth into hugetlb reserved regions (Konrad Rzeszutek) [253313] {CVE-2007-3739}
[2.6.18-8.1.9.el5] - [misc] cpuset information leak (Prarit Bhargava ) [245773] {CVE-2007-2875} - [net] ip_conntrack_sctp: fix remotely triggerable panic (Don Howard ) [245774] {CVE-2007-2876} - [misc] Overflow in CAPI subsystem (Anton Arapov ) [232260] {CVE-2007-1217} - [CIFS] fix signing sec= mount options (Jeff Layton ) [253315] {CVE-2007-3843} - [CIFS] respect umask when unix extensions are enabled (Jeff Layton ) [253314] {CVE-2007-3740} - [misc] i915_dma: fix batch buffer security bit for i965 chipsets (Aristeu Rozanski ) [252305] {CVE-2007-3851} - [fs] - Move ms-dos compat ioctl to ms-dos dir (Eric Sandeen ) [253317] - [fs] - fix VFAT compat ioctls on 64-bit systems (Eric Sandeen ) [253317] {CVE-2007-2878}
Affected Software/OS: 'kernel, ocfs2-2.6.18-8.1.10.0.1.el5, oracleasm-2.6.18-8.1.10.0.1.el5' package(s) on Oracle Linux 5.
Solution: Please install the updated package(s).
CVSS Score: 6.9
CVSS Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
|