Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51006
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2003:145
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory RHSA-2003:145.

The Linux kernel handles the basic functions of the operating system.

A ptrace-related vulnerability has been discovered that could allow a local
user to gain elevated (root) privileges without authorization. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CVE-2003-0127 to this issue.

A flaw has been discovered that could potentially lead to data corruption.
The scenario only occurs while performing memory mapped file I/O, where
the file is simultaneously unlinked and the corresponding file blocks
reallocated. Furthermore, the memory mapped must be to a partial page at
the end of a file on an ext3 file system. As such, Red Hat considers this
scenario unlikely.

A flaw has been found in several hash table implementations in the kernel
networking code. A remote attacker could send packets with carefully
chosen, forged source addresses in such a way as to make every routing
cache entry get hashed into the same hash chain. The result would be that
the kernel would use a disproportionate amount of processor time to deal
with new packets, resulting in a remote denial of service attack. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2003-0244 to this issue.

In addition, the following drivers have been updated to the version indicated:

- e1000: 4.4.19-k1
- e100: 2.1.29-k2
- ips: 6.00.26
- qla2100, qla2200, qla2300: v6.04.01
- tg3 driver to 1.4c
- cciss driver to 2.4.44
- mpt fusion: 2.05.00
- aic7xxx to 6.2.32
- aic79xx to 1.3.6

If the system is configured to use alternate drivers, we recommend applying
the kudzu errata RHEA-2003:132 prior to updating the kernel.

The updated kernel also adds support for the IBM x450 platform and the
Madison processor, and incorporates improved support for the hugetlb file
system. This file system makes efficient use of the large page size
support that the Itanium architecture provides.

All users should upgrade to these errata packages, which address these issues.

Solution:
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

http://rhn.redhat.com/errata/RHSA-2003-145.html

Risk factor : High

CVSS Score:
7.2

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0127
Caldera Security Advisory: CSSA-2003-020.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-020.0.txt
CERT/CC vulnerability note: VU#628849
http://www.kb.cert.org/vuls/id/628849
Debian Security Information: DSA-270 (Google Search)
http://www.debian.org/security/2003/dsa-270
Debian Security Information: DSA-276 (Google Search)
http://www.debian.org/security/2003/dsa-276
Debian Security Information: DSA-311 (Google Search)
http://www.debian.org/security/2003/dsa-311
Debian Security Information: DSA-312 (Google Search)
http://www.debian.org/security/2003/dsa-312
Debian Security Information: DSA-332 (Google Search)
http://www.debian.org/security/2003/dsa-332
Debian Security Information: DSA-336 (Google Search)
http://www.debian.org/security/2003/dsa-336
Debian Security Information: DSA-423 (Google Search)
http://www.debian.org/security/2004/dsa-423
Debian Security Information: DSA-495 (Google Search)
http://www.debian.org/security/2004/dsa-495
En Garde Linux Advisory: ESA-20030318-009
En Garde Linux Advisory: ESA-20030515-017
http://marc.info/?l=bugtraq&m=105301461726555&w=2
http://security.gentoo.org/glsa/glsa-200303-17.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2003:038
http://www.mandriva.com/security/advisories?name=MDKSA-2003:039
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A254
RedHat Security Advisories: RHSA-2003:088
http://rhn.redhat.com/errata/RHSA-2003-088.html
RedHat Security Advisories: RHSA-2003:098
http://rhn.redhat.com/errata/RHSA-2003-098.html
http://www.redhat.com/support/errata/RHSA-2003-103.html
http://www.redhat.com/support/errata/RHSA-2003-145.html
SuSE Security Announcement: SuSE-SA:2003:021 (Google Search)
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html
Common Vulnerability Exposure (CVE) ID: CVE-2003-0244
BugTraq ID: 7601
http://www.securityfocus.com/bid/7601
Bugtraq: 20030618 [slackware-security] 2.4.21 kernels available (SSA:2003-168-01) (Google Search)
http://marc.info/?l=bugtraq&m=105595901923063&w=2
Debian Security Information: DSA-442 (Google Search)
http://www.debian.org/security/2004/dsa-442
http://www.mandriva.com/security/advisories?name=MDKSA-2003:066
http://www.mandriva.com/security/advisories?name=MDKSA-2003:074
http://marc.info/?l=linux-kernel&m=104956079213417
http://www.enyo.de/fw/security/notes/linux-dst-cache-dos.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A261
http://www.redhat.com/support/errata/RHSA-2003-147.html
http://www.redhat.com/support/errata/RHSA-2003-172.html
http://www.secunia.com/advisories/8786/
http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0073.html
XForce ISS Database: data-algorithmic-complexity-dos(15382)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15382
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.