Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123907
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2012-0721)
Summary:The remote host is missing an update for the 'kernel, ocfs2-2.6.18-308.8.2.el5, oracleasm-2.6.18-308.8.2.el5' package(s) announced via the ELSA-2012-0721 advisory.
Description:Summary:
The remote host is missing an update for the 'kernel, ocfs2-2.6.18-308.8.2.el5, oracleasm-2.6.18-308.8.2.el5' package(s) announced via the ELSA-2012-0721 advisory.

Vulnerability Insight:
kernel:

[2.6.18-308.8.2.el5]
- [xen] x86_64: check address on trap handlers or guest callbacks (Paolo Bonzini) [813430 813431] {CVE-2012-0217}
- [xen] x86_64: Do not execute sysret with a non-canonical return address (Paolo Bonzini) [813430 813431] {CVE-2012-0217}
- [xen] x86: prevent hv boot on AMD CPUs with Erratum 121 (Laszlo Ersek) [824969 824970]

ocfs2:

[1.4.10]
- ocfs2/dlm: Cleanup mlogs in dlmthread.c dlmast.c and dlmdomain.c
- ocfs2/dlm: make existing conversion precedent over new lock
- ocfs2/dlm: Cleanup dlmdebug.c
- ocfs2/dlm: Minor cleanup
- ocfs2/dlm: Hard code the values for enums
- ocfs2: Wakeup down convert thread just after clearing OCFS2 LOCK UPCONVERT FINISHING
- ocfs2/dlm: Take inflight reference count for remotely mastered resources too
- ocfs2/dlm: dlmlock remote needs to account for remastery
- ocfs2: Add some trace log for orphan scan
- ocfs2: Remove unused old id in ocfs2_commit_cache
- ocfs2: Remove obsolete comments before ocfs2_start_trans
- ocfs2: Initialize the bktcnt variable properly and call it bucket_count
- ocfs2: Use cpu to le16 for e leaf clusters in ocfs2_bg_discontig_add_extent
- ocfs2: validate bg free bits count after update
- ocfs2: cluster Pin the remote node item in configfs
- ocfs2: Release buffer head in case of error in ocfs2_double_lock
- ocfs2: optimize ocfs2 check dir entry with unlikely() annotations
- ocfs2: Little refactoring against ocfs2 iget
- ocfs2: Initialize data ac might be used uninitializ
- ocfs2 Skip mount recovery for hard ro mounts
- ocfs2: make direntry invalid when deleting it
- ocfs2: commit trans in error
- ocfs2: Fix deadlock when allocating page
- ocfs2: Avoid livelock in ocfs2 readpage

Affected Software/OS:
'kernel, ocfs2-2.6.18-308.8.2.el5, oracleasm-2.6.18-308.8.2.el5' package(s) on Oracle Linux 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-0217
Cert/CC Advisory: TA12-164A
http://www.us-cert.gov/cas/techalerts/TA12-164A.html
CERT/CC vulnerability note: VU#649219
http://www.kb.cert.org/vuls/id/649219
Debian Security Information: DSA-2501 (Google Search)
http://www.debian.org/security/2012/dsa-2501
Debian Security Information: DSA-2508 (Google Search)
http://www.debian.org/security/2012/dsa-2508
https://www.exploit-db.com/exploits/28718/
https://www.exploit-db.com/exploits/46508/
FreeBSD Security Advisory: FreeBSD-SA-12:04
http://security.freebsd.org/advisories/FreeBSD-SA-12:04.sysret.asc
http://security.gentoo.org/glsa/glsa-201309-24.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
http://lists.xen.org/archives/html/xen-announce/2012-06/msg00001.html
http://lists.xen.org/archives/html/xen-devel/2012-06/msg01072.html
Microsoft Security Bulletin: MS12-042
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-042
NETBSD Security Advisory: NetBSD-SA2012-003
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2012-003.txt.asc
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15596
http://secunia.com/advisories/55082
Common Vulnerability Exposure (CVE) ID: CVE-2012-2934
BugTraq ID: 53961
http://www.securityfocus.com/bid/53961
http://support.amd.com/us/Processor_TechDocs/25759.pdf
http://lists.xen.org/archives/html/xen-announce/2012-06/msg00002.html
http://secunia.com/advisories/51413
SuSE Security Announcement: openSUSE-SU-2012:1572 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00017.html
SuSE Security Announcement: openSUSE-SU-2012:1573 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-11/msg00018.html
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.