Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.50291
Category:Fedora Local Security Checks
Title:Fedora Core 1 FEDORA-2003-046 (kernel)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to kernel
announced via advisory FEDORA-2003-046.

The kernel package contains the Linux kernel (vmlinuz), the core of your
Red Hat Linux operating system. The kernel handles the basic functions
of the operating system: memory allocation, process allocation, device
input and output, etc.

Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux
kernel versions 2.4.23 and previous which may allow a local attacker to
gain root privileges. No exploit is currently available
however, it is
believed that this issue is exploitable (although not trivially.) The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2003-0985 to this issue.

All users are advised to upgrade to these errata packages, which contain a
backported security patch that corrects this issue.

Red Hat would like to thank Paul Starzetz from ISEC for disclosing this
issue as well as Andrea Arcangeli and Solar Designer for working on the patch.

These packages also contain a fix for a minor information leak in the real
time clock (rtc) routines. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2003-0984 to this issue.


* Wed Dec 24 2003 Dave Jones
- Fix mremap corner case.

* Tue Dec 23 2003 Dave Jones
- Numerous USB fixes (#110307, #90442, #107929, #110872)

* Tue Dec 16 2003 Dave Jones
- Fix leak in CDROM IOCTL. (#112249)

Solution: Apply the appropriate updates.
http://www.fedoranews.org/updates/FEDORA-2003-046.shtml
http://isec.pl/vulnerabilities/isec-0013-mremap.txt

Risk factor : Medium

CVSS Score:
4.6

Cross-Ref: BugTraq ID: 9154
Common Vulnerability Exposure (CVE) ID: CVE-2003-0984
http://www.securityfocus.com/bid/9154
Bugtraq: 20040112 SmoothWall Project Security Advisory SWP-2004:001 (Google Search)
http://marc.info/?l=bugtraq&m=107394143105081&w=2
Conectiva Linux advisory: CLA-2004:799
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000799
Debian Security Information: DSA-1067 (Google Search)
http://www.debian.org/security/2006/dsa-1067
Debian Security Information: DSA-1069 (Google Search)
http://www.debian.org/security/2006/dsa-1069
Debian Security Information: DSA-1070 (Google Search)
http://www.debian.org/security/2006/dsa-1070
Debian Security Information: DSA-1082 (Google Search)
http://www.debian.org/security/2006/dsa-1082
En Garde Linux Advisory: ESA-20040105-001
http://www.linuxsecurity.com/advisories/engarde_advisory-3904.html
http://www.redhat.com/archives/fedora-announce-list/2004-January/msg00000.html
http://www.mandriva.com/security/advisories?name=MDKSA-2004:001
http://www.osvdb.org/3317
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1013
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A859
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9406
http://www.redhat.com/support/errata/RHSA-2003-417.html
http://www.redhat.com/support/errata/RHSA-2004-188.html
http://www.securitytracker.com/id?1008594
http://secunia.com/advisories/10533
http://secunia.com/advisories/10536
http://secunia.com/advisories/10537
http://secunia.com/advisories/10538
http://secunia.com/advisories/10555
http://secunia.com/advisories/10582
http://secunia.com/advisories/10583
http://secunia.com/advisories/20162
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
SuSE Security Announcement: SuSE-SA:2003:049 (Google Search)
http://www.novell.com/linux/security/advisories/2003_049_kernel.html
XForce ISS Database: linux-rtc-memory-leak(13943)
https://exchange.xforce.ibmcloud.com/vulnerabilities/13943
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.