English | Deutsch | Español | Português
 UserID:
 Passwd:
new user
 About:   Dedicated  | Advanced  | Standard  | Recurring  | No Risk  | Desktop  | Basic  | Single  | Security Seal  | FAQ
  Price/Feature Summary  | Order  | New Vulnerabilities  | Confidentiality  | Vulnerability Search
 Vulnerability   
Search   
    Search 75516 CVE descriptions
and 39786 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51348
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLA-2004:846
Summary:Conectiva Security Advisory CLA-2004:846
Description:
The remote host is missing updates announced in
advisory CLA-2004:846.

The Linux kernel is responsible for handling the basic functions of
the GNU/Linux operating system.

This announcement fixes the following vulnerabilities:

1. Vicam USB driver denial of service (CVE-2004-0075[1])
2. OSS denial of service (CVE-2004-0178[2])
3. ISO-9660 buffer overflow vulnerability[3] (CVE-2004-0109[4])
4. R128 DRI local privileges escalation (CVE-2004-0003[5])
5. do_fork memory leak (CVE-2004-0427[6])
6. Infoleak on filesystems (CVE-2004-0133[8], CVE-2004-0177[9])
7. Buffer overflow at panic state (CVE-2004-0394[10])
8. Sparse bugs (CVE-2004-0495[11])

This announcement adds missing parts of the sparse corrections done
to the Linux kernel in our previous announcement[12].

Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:846
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004

Risk factor : Medium
Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0075
Conectiva Linux advisory: CLA-2004:846
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2004:015
http://www.redhat.com/support/errata/RHSA-2004-065.html
http://www.redhat.com/support/errata/RHSA-2005-293.html
SuSE Security Announcement: SuSE-SA:2004:005 (Google Search)
http://www.novell.com/linux/security/advisories/2004_05_linux_kernel.html
Computer Incident Advisory Center Bulletin: O-082
http://www.ciac.org/ciac/bulletins/o-082.shtml
BugTraq ID: 9690
http://www.securityfocus.com/bid/9690
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:836
XForce ISS Database: linux-vicam-dos(15246)
http://xforce.iss.net/xforce/xfdb/15246
Common Vulnerability Exposure (CVE) ID: CVE-2004-0178
Debian Security Information: DSA-479 (Google Search)
http://www.debian.org/security/2004/dsa-479
Debian Security Information: DSA-480 (Google Search)
http://www.debian.org/security/2004/dsa-480
Debian Security Information: DSA-481 (Google Search)
http://www.debian.org/security/2004/dsa-481
Debian Security Information: DSA-482 (Google Search)
http://www.debian.org/security/2004/dsa-482
Debian Security Information: DSA-489 (Google Search)
http://www.debian.org/security/2004/dsa-489
Debian Security Information: DSA-491 (Google Search)
http://www.debian.org/security/2004/dsa-491
Debian Security Information: DSA-495 (Google Search)
http://www.debian.org/security/2004/dsa-495
http://security.gentoo.org/glsa/glsa-200407-02.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:029
http://www.redhat.com/support/errata/RHSA-2004-413.html
http://www.redhat.com/support/errata/RHSA-2004-437.html
SGI Security Advisory: 20040804-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040804-01-U.asc
http://linux.bkbits.net:8080/linux-2.4/cset@404ce5967rY2Ryu6Z_uNbYh643wuFA
Computer Incident Advisory Center Bulletin: O-121
http://www.ciac.org/ciac/bulletins/o-121.shtml
Computer Incident Advisory Center Bulletin: O-127
http://www.ciac.org/ciac/bulletins/o-127.shtml
Computer Incident Advisory Center Bulletin: O-193
http://www.ciac.org/ciac/bulletins/o-193.shtml
BugTraq ID: 9985
http://www.securityfocus.com/bid/9985
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9427
XForce ISS Database: linux-sound-blaster-dos(15868)
http://xforce.iss.net/xforce/xfdb/15868
Common Vulnerability Exposure (CVE) ID: CVE-2004-0109
http://www.idefense.com/application/poi/display?id=101&type=vulnerabilities
En Garde Linux Advisory: ESA-20040428-004
http://www.linuxsecurity.com/advisories/engarde_advisory-4285.html
http://www.redhat.com/support/errata/RHSA-2004-105.html
http://www.redhat.com/support/errata/RHSA-2004-106.html
RedHat Security Advisories: RHSA-2004:166
http://rhn.redhat.com/errata/RHSA-2004-166.html
http://www.redhat.com/support/errata/RHSA-2004-183.html
SGI Security Advisory: 20040405-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040405-01-U.asc
SGI Security Advisory: 20040504-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc
SuSE Security Announcement: SuSE-SA:2004:009 (Google Search)
http://www.novell.com/linux/security/advisories/2004_09_kernel.html
http://marc.theaimsgroup.com/?l=bugtraq&m=108213675028441&w=2
TurboLinux Advisory: TLSA-2004-14
http://www.turbolinux.com/security/2004/TLSA-2004-14.txt
BugTraq ID: 10141
http://www.securityfocus.com/bid/10141
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:940
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10733
http://secunia.com/advisories/11361
http://secunia.com/advisories/11362
http://secunia.com/advisories/11373
http://secunia.com/advisories/11464
http://secunia.com/advisories/11469
http://secunia.com/advisories/11470
http://secunia.com/advisories/11486
http://secunia.com/advisories/11494
http://secunia.com/advisories/11518
http://secunia.com/advisories/11626
http://secunia.com/advisories/11861
http://secunia.com/advisories/11891
http://secunia.com/advisories/11986
http://secunia.com/advisories/12003
XForce ISS Database: linux-iso9660-bo(15866)
http://xforce.iss.net/xforce/xfdb/15866
Common Vulnerability Exposure (CVE) ID: CVE-2004-0003
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:029
http://www.redhat.com/support/errata/RHSA-2004-044.html
Computer Incident Advisory Center Bulletin: O-126
http://www.ciac.org/ciac/bulletins/o-126.shtml
Computer Incident Advisory Center Bulletin: O-145
http://www.ciac.org/ciac/bulletins/o-145.shtml
BugTraq ID: 9570
http://www.securityfocus.com/bid/9570
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9204
http://secunia.com/advisories/10782
http://secunia.com/advisories/10911
http://secunia.com/advisories/10912
http://secunia.com/advisories/11202
http://secunia.com/advisories/11369
http://secunia.com/advisories/11370
http://secunia.com/advisories/11376
http://secunia.com/advisories/12075
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1017
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:834
XForce ISS Database: linux-r128-gain-priviliges(15029)
http://xforce.iss.net/xforce/xfdb/15029
Common Vulnerability Exposure (CVE) ID: CVE-2004-0427
http://marc.theaimsgroup.com/?l=linux-kernel&m=108139073506983&w=2
Debian Security Information: DSA-1070 (Google Search)
http://www.debian.org/security/2006/dsa-1070
Debian Security Information: DSA-1067 (Google Search)
http://www.debian.org/security/2006/dsa-1067
Debian Security Information: DSA-1069 (Google Search)
http://www.debian.org/security/2006/dsa-1069
Debian Security Information: DSA-1082 (Google Search)
http://www.debian.org/security/2006/dsa-1082
http://fedoranews.org/updates/FEDORA-2004-111.shtml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:037
http://www.redhat.com/support/errata/RHSA-2004-255.html
http://www.redhat.com/support/errata/RHSA-2004-260.html
http://www.redhat.com/support/errata/RHSA-2004-327.html
SGI Security Advisory: 20040505-01-U
ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc
SuSE Security Announcement: SuSE-SA:2004:010 (Google Search)
http://www.novell.com/linux/security/advisories/2004_10_kernel.html
http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA
http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A
Computer Incident Advisory Center Bulletin: O-164
http://www.ciac.org/ciac/bulletins/o-164.shtml
BugTraq ID: 10221
http://www.securityfocus.com/bid/10221
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10297
http://secunia.com/advisories/11429
http://secunia.com/advisories/11541
http://secunia.com/advisories/11892
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2819
http://secunia.com/advisories/20162
http://secunia.com/advisories/20163
http://secunia.com/advisories/20202
http://secunia.com/advisories/20338
XForce ISS Database: linux-dofork-memory-leak(16002)
http://xforce.iss.net/xforce/xfdb/16002
Common Vulnerability Exposure (CVE) ID: CVE-2004-0133
BugTraq ID: 10151
http://www.securityfocus.com/bid/10151
XForce ISS Database: linux-xfs-info-disclosure(15901)
http://xforce.iss.net/xforce/xfdb/15901
Common Vulnerability Exposure (CVE) ID: CVE-2004-0177
https://bugzilla.fedora.us/show_bug.cgi?id=2336
http://www.redhat.com/support/errata/RHSA-2004-504.html
http://www.redhat.com/support/errata/RHSA-2004-505.html
http://linux.bkbits.net:8080/linux-2.4/cset@4056b368s6vpJbGWxDD_LhQNYQrdzQ
BugTraq ID: 10152
http://www.securityfocus.com/bid/10152
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10556
XForce ISS Database: linux-ext3-info-disclosure(15867)
http://xforce.iss.net/xforce/xfdb/15867
Common Vulnerability Exposure (CVE) ID: CVE-2004-0394
http://lwn.net/Articles/81773/
BugTraq ID: 10233
http://www.securityfocus.com/bid/10233
XForce ISS Database: linux-panic-bo(15953)
http://xforce.iss.net/xforce/xfdb/15953
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 39786 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

New User Registration
Email:
UserID:
Passwd:
Please email me your monthly newsletters, informing the latest services, improvements & surveys.
Please email me a vulnerability test announcement whenever a new test is added.
   Privacy
Registered User Login
 
UserID:   
Passwd:  

 Forgot userid or passwd?
Email/Userid:




Home | About Us | Contact Us | Partner Programs | Privacy | Mailing Lists | Abuse
Security Audits | Managed DNS | Network Monitoring | Site Analyzer | Internet Research Reports
Web Probe | Whois

© 1998-2014 E-Soft Inc. All rights reserved.