Description: | Description:
The remote host is missing an update to kernel announced via advisory FEDORA-2008-4043.
The kernel package contains the Linux kernel (vmlinuz), the core of any Linux operating system. The kernel handles the basic functions of the operating system: memory allocation, process allocation, device input and output, etc.
Update Information:
Update to Linux kernel version 2.6.23.17: http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.16 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23.17 Additionally, following security fixes were backported:
CVE-2008-1669 - SMP ordering hole in fcntl_setlk() CVE-2008-1615 - Denial-of-service on x86_64 architecture.
ChangeLog:
* Wed May 14 2008 Chuck Ebbert 2.6.23.17-88 - Increment version. * Wed May 14 2008 Chuck Ebbert 2.6.23.17-87 - Security fix: CVE-2008-1669 (taken from 2.6.25.2)
References:
[ 1 ] Bug #431430 - CVE-2008-1615 kernel: ptrace: Unprivileged crash on x86_64 %cs corruption https://bugzilla.redhat.com/show_bug.cgi?id=431430 [ 2 ] Bug #443433 - CVE-2008-1669 kernel: add rcu_read_lock() to fcheck() in both dnotify, locks.c and fix fcntl store/load race in locks.c https://bugzilla.redhat.com/show_bug.cgi?id=443433
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kernel' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-4043
Risk factor : High
CVSS Score: 7.2
|