Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58089
Category:Mandrake Local Security Checks
Title:Mandrake Security Advisory MDKSA-2007:047 (kernel)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to kernel
announced via advisory MDKSA-2007:047.

Some vulnerabilities were discovered and corrected in the Linux 2.6
kernel:

A double free vulnerability in the squashfs module could allow a local
user to cause a Denial of Service by mounting a crafted squashfs
filesystem (CVE-2006-5701).

The zlib_inflate function allows local users to cause a crash via a
malformed filesystem that uses zlib compression that triggers memory
corruption (CVE-2006-5823).

The key serial number collision avoidance code in the key_alloc_serial
function in kernels 2.6.9 up to 2.6.20 allows local users to cause a
crash via vectors thatr trigger a null dereference (CVE-2007-0006).

The provided packages are patched to fix these vulnerabilities. All
users are encouraged to upgrade to these updated kernels immediately
and reboot to effect the fixes.

In addition to these security fixes, other fixes have been included
such as:

- New drivers: nozomi, UVC
- Fixed SiS SATA support for chips on 966/968 bridges
- Fixed issues in squashfs by updating to 3.2 (#27008)
- Added support for SiS968 bridgest to the sis190 bridge
- Fixed JMicron cable detection
- Added /proc/config.gz support and enabled kexec on x86_64
- Other minor fixes

To update your kernel, please follow the directions located at:

http://www.mandriva.com/en/security/kernelupdate

Affected: 2007.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2007:047

Risk factor : Medium

CVSS Score:
4.9

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-5701
BugTraq ID: 20870
http://www.securityfocus.com/bid/20870
http://www.mandriva.com/security/advisories?name=MDKSA-2007:047
http://projects.info-pull.com/mokb/MOKB-02-11-2006.html
http://secunia.com/advisories/22655
http://secunia.com/advisories/23361
http://secunia.com/advisories/23384
http://secunia.com/advisories/24259
http://www.ubuntu.com/usn/usn-395-1
XForce ISS Database: linux-squashfs-doublefree-dos(29967)
https://exchange.xforce.ibmcloud.com/vulnerabilities/29967
Common Vulnerability Exposure (CVE) ID: CVE-2006-5823
Bugtraq: 20070615 rPSA-2007-0124-1 kernel xen (Google Search)
http://www.securityfocus.com/archive/1/471457
Debian Security Information: DSA-1503 (Google Search)
http://www.debian.org/security/2008/dsa-1503
Debian Security Information: DSA-1504 (Google Search)
http://www.debian.org/security/2008/dsa-1504
http://www.mandriva.com/security/advisories?name=MDKSA-2007:060
http://projects.info-pull.com/mokb/MOKB-07-11-2006.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10588
RedHat Security Advisories: RHSA-2007:0014
http://rhn.redhat.com/errata/RHSA-2007-0014.html
RedHat Security Advisories: RHSA-2007:0436
http://rhn.redhat.com/errata/RHSA-2007-0436.html
http://secunia.com/advisories/22767
http://secunia.com/advisories/23474
http://secunia.com/advisories/23997
http://secunia.com/advisories/24098
http://secunia.com/advisories/24206
http://secunia.com/advisories/24482
http://secunia.com/advisories/25630
http://secunia.com/advisories/25691
http://secunia.com/advisories/29058
SuSE Security Announcement: SUSE-SA:2006:079 (Google Search)
http://www.novell.com/linux/security/advisories/2006_79_kernel.html
http://www.ubuntu.com/usn/usn-416-1
Common Vulnerability Exposure (CVE) ID: CVE-2007-0006
20070615 rPSA-2007-0124-1 kernel xen
22539
http://www.securityfocus.com/bid/22539
24109
http://secunia.com/advisories/24109
24259
24300
http://secunia.com/advisories/24300
24429
http://secunia.com/advisories/24429
24482
24547
http://secunia.com/advisories/24547
24752
http://secunia.com/advisories/24752
25691
MDKSA-2007:047
MDKSA-2007:060
RHSA-2007:0085
http://www.redhat.com/support/errata/RHSA-2007-0085.html
RHSA-2007:0099
http://www.redhat.com/support/errata/RHSA-2007-0099.html
SUSE-SA:2007:021
http://www.novell.com/linux/security/advisories/2007_21_kernel.html
USN-451-1
http://www.ubuntu.com/usn/usn-451-1
http://bugzilla.kernel.org/show_bug.cgi?id=7727
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=227495
https://issues.rpath.com/browse/RPL-1097
oval:org.mitre.oval:def:9829
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9829
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.