|
Family: Ubuntu Local Security Checks --> Category: infos
USN187-1 : linux-source-2.6.10, linux-source-2.6.8.1 vulnerabilities Vulnerability Scan
Vulnerability Scan Summary linux-source-2.6.10, linux-source-2.6.8.1 vulnerabilities
Detailed Explanation for this Vulnerability Test
Synopsis :
These remote packages are missing security patches :
- linux-doc-2.6.10
- linux-doc-2.6.8.1
- linux-headers-2.6.10-5
- linux-headers-2.6.10-5-386
- linux-headers-2.6.10-5-686
- linux-headers-2.6.10-5-686-smp
- linux-headers-2.6.10-5-amd64-generic
- linux-headers-2.6.10-5-amd64-k8
- linux-headers-2.6.10-5-amd64-k8-smp
- linux-headers-2.6.10-5-amd64-xeon
- linux-headers-2.6.10-5-k7
- linux-headers-2.6.10-5-k7-smp
- linux-headers-2.6.10-5-power3
- linux-headers-2.6.10-5-power3-smp
- linux-header
[...]
Description :
A Denial of Service vulnerability was detected in the stack segment
fault handler. A local attacker could exploit this by causing stack
fault exceptions under special circumstances (scheduling), which lead
to a kernel crash. (CVE-2005-1767)
Vasiliy Averin discovered a Denial of Service vulnerability in the
"tiocgdev" ioctl call and in the "routing_ioctl" function. By calling
fget() and fput() in special ways, a local attacker could exploit this
to destroy file descriptor structures and crash the kernel.
(CVE-2005-3044)
Solution :
Upgrade to :
- linux-doc-2.6.10-2.6.10-34.6 (Ubuntu 5.04)
- linux-doc-2.6.8.1-2.6.8.1-16.23 (Ubuntu 4.10)
- linux-headers-2.6.10-5-2.6.10-34.6 (Ubuntu 5.04)
- linux-headers-2.6.10-5-386-2.6.10-34.6 (Ubuntu 5.04)
- linux-headers-2.6.10-5-686-2.6.10-34.6 (Ubuntu 5.04)
- linux-headers-2.6.10-5-686-smp-2.6.10-34.6 (Ubuntu 5.04)
- linux-headers-2.6.10-5-amd64-generic-2.6.10-34.6 (Ubuntu 5.04)
- linux-headers-2.6.10-5-amd64-k8-2.6.10-34.6 (Ubuntu 5.04)
- linux-headers-2.6.10-5-amd64-k8-smp-2.6.10-34.6 (Ubuntu 5
[...]
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|