Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53013
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-137-1 (linux-source-2.6.8.1)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to linux-source-2.6.8.1
announced via advisory USN-137-1.

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)

Alexander Nyberg discovered that ptrace() insufficiently validated
addresses on the amd64 platform so that it was possible to set an
invalid segment base. A local attacker could exploit this to crash the
kernel. This does not affect the i386 and powerpc platforms in any
way. (CVE-2005-0756)

Chris Wright discovered that the mmap() function could create illegal
memory maps (using the mmap function) with the start address
pointing beyond the end address. A local user could exploit this to
crash the kernel or possibly even execute arbitrary code with kernel
privileges. (CVE-2005-1265)

Solution:
The problem can be corrected by upgrading the affected package to
version 2.6.8.1-16.19 (for Ubuntu 4.10), or 2.6.10-34.2 (for Ubuntu
5.04). After doing a standard system upgrade you need to reboot your
computer to effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-137-1

Risk factor : Medium

CVSS Score:
2.1

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0756
13891
http://www.securityfocus.com/bid/13891
17002
http://secunia.com/advisories/17002
17073
http://secunia.com/advisories/17073
18056
http://secunia.com/advisories/18056
18059
http://secunia.com/advisories/18059
ADV-2005-1878
http://www.vupen.com/english/advisories/2005/1878
DSA-921
http://www.debian.org/security/2005/dsa-921
DSA-922
http://www.debian.org/security/2005/dsa-922
FLSA:157459-2
http://www.securityfocus.com/archive/1/428058/100/0/threaded
FLSA:157459-3
http://www.securityfocus.com/archive/1/427980/100/0/threaded
RHSA-2005:514
http://www.redhat.com/support/errata/RHSA-2005-514.html
RHSA-2005:663
http://www.redhat.com/support/errata/RHSA-2005-663.html
USN-137-1
https://usn.ubuntu.com/137-1/
oval:org.mitre.oval:def:11119
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11119
Common Vulnerability Exposure (CVE) ID: CVE-2005-1265
1014152
http://securitytracker.com/id?1014152
13893
http://www.securityfocus.com/bid/13893
oval:org.mitre.oval:def:10466
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10466
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.