Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54014
Category:SuSE Local Security Checks
Title:SuSE Security Advisory SUSE-SA:2005:021 (kernel)
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory SUSE-SA:2005:021.

This Linux kernel security update fixes a problem within the Bluetooth
kernel stack which can be used by a local attacker to gain root access or
crash the machine.

To exploit this problem, the Bluetooth modules do not need to be
loaded since they are auto loaded on demand (except in products mentioned
below).

This problem has been assigned the Mitre CVE ID CVE-2005-0750.

Updated packages have been provided for the default affected products:
- SUSE Linux 8.2, 9.0 and 9.2 (both i386 and x86_64) - SUSE Linux
Enterprise Server 8 (i386, ia64 and x86_64) - SUSE Linux Desktop 1.0

Other architectures do not have Bluetooth enabled.
Also SUSE Linux 9.1, SUSE Linux Enterprise Server 9 and Novell Linux
Desktop 9 are not affected by default since the Bluetooth module is not
auto loaded. These will get the patch with the next security update.

Solution:
Update your system with the packages as indicated in
the referenced security advisory.

http://www.securityspace.com/smysecure/catid.html?in=SUSE-SA:2005:021

Risk factor : High

CVSS Score:
7.2

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0750
BugTraq ID: 12911
http://www.securityfocus.com/bid/12911
Bugtraq: 20050327 local root security bug in linux >= 2.4.6 <= 2.4.30-rc1 and 2.6.x.y <= 2.6.11.5 (Google Search)
http://marc.info/?l=bugtraq&m=111204562102633&w=2
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152532
http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032913.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11719
http://www.redhat.com/support/errata/RHSA-2005-283.html
http://www.redhat.com/support/errata/RHSA-2005-284.html
http://www.redhat.com/support/errata/RHSA-2005-293.html
http://www.redhat.com/support/errata/RHSA-2005-366.html
XForce ISS Database: kernel-bluezsockcreate-integer-underflow(19844)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19844
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.