Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61870
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-662-2 (linux-ubuntu-modules-2.6.22/24)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to linux-ubuntu-modules-2.6.22/24
announced via advisory USN-662-2.

A security issue affects the following Ubuntu releases:

Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

Details follow:

USN-662-1 fixed vulnerabilities in ndiswrapper in Ubuntu 8.10.
This update provides the corresponding updates for Ubuntu 8.04 and 7.10.

Original advisory details:

Anders Kaseorg discovered that ndiswrapper did not correctly handle long
ESSIDs. For a system using ndiswrapper, a physically near-by attacker
could generate specially crafted wireless network traffic and execute
arbitrary code with root privileges. (CVE-2008-4395)

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 7.10:
linux-ubuntu-modules-2.6.22-15-386 2.6.22-15.40
linux-ubuntu-modules-2.6.22-15-generic 2.6.22-15.40
linux-ubuntu-modules-2.6.22-15-rt 2.6.22-15.40
linux-ubuntu-modules-2.6.22-15-server 2.6.22-15.40

Ubuntu 8.04 LTS:
linux-ubuntu-modules-2.6.24-21-386 2.6.24-21.33
linux-ubuntu-modules-2.6.24-21-generic 2.6.24-21.33
linux-ubuntu-modules-2.6.24-21-rt 2.6.24-21.33
linux-ubuntu-modules-2.6.24-21-server 2.6.24-21.33

After a standard system upgrade you need to reboot your computer to
effect the necessary changes.

http://www.securityspace.com/smysecure/catid.html?in=USN-662-2

Risk factor : Critical

CVSS Score:
8.3

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-4395
BugTraq ID: 32118
http://www.securityfocus.com/bid/32118
http://www.mail-archive.com/frugalware-git@frugalware.org/msg22366.html
http://www.securitytracker.com/id?1021142
http://secunia.com/advisories/32509
SuSE Security Announcement: SUSE-SA:2008:057 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00001.html
http://www.ubuntu.com/usn/usn-662-1
http://www.ubuntu.com/usn/usn-662-2
XForce ISS Database: linux-kernel-ndiswrapper-bo(46437)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46437
CopyrightCopyright (c) 2008 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.