[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SA:2009:060 -- SUSE kernel remote denial of service

ID: oval:org.secpod.oval:def:400071Date: (C)2012-01-31   (M)2024-02-19
Class: PATCHFamily: unix




The SUSE Linux Enterprise 11 and openSUSE 11.1 Kernel was updated to 2.6.27.39 fixing various bugs and security issues. Following security issues have been fixed: CVE-2009-3547: A race condition during pipe open could be used by local attackers to cause a denial of service. CVSS v2 Base Score: 6.9 CVE-2009-2910: On x86_64 systems a information leak of high register contents was fixed. CVSS v2 Base Score: 4.9 CVE-2009-2903: Memory leak in the AppleTalk subsystem in the Linux kernel when the AppleTalk and ipddp modules are loaded but the ipddp &qt N &qt device is not found, allows remote attackers to cause a denial of service via IP-DDP datagrams. CVSS v2 Base Score: 7.1 CVE-2009-3621: net/unix/af_unix.c in the Linux kernel allows local users to cause a denial of service by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket. CVSS v2 Base Score: 4.9 CVE-2005-4881: The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue existed because of an incomplete fix for CVE-2005-4881. CVSS v2 Base Score: 4.9 CVE-2009-3620: The ATI Rage 128 driver in the Linux kernel does not properly verify Concurrent Command Engine state initialization, which allows local users to cause a denial of service or possibly gain privileges via unspecified ioctl calls. CVSS v2 Base Score: 4.9 CVE-2009-3726: The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel allows remote NFS servers to cause a denial of service by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state. CVSS v2 Base Score: 7.8 CVE-2009-3286: NFSv4 in the Linux kernel does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails. CVSS v2 Base Score: 4.6 Also the rio and sx serial multi port card drivers were disabled via /etc/modprobe.d/generic_serial-blacklist due to bugs. A complete list of changes can be found in the RPM changelog.

Platform:
openSUSE 11.1
Product:
kernel
Reference:
SUSE-SA:2009:060
CVE-2005-4881
CVE-2009-2903
CVE-2009-2910
CVE-2009-3286
CVE-2009-3547
CVE-2009-3612
CVE-2009-3620
CVE-2009-3621
CVE-2009-3726
CVE    9
CVE-2005-4881
CVE-2009-3620
CVE-2009-3621
CVE-2009-3612
...
CPE    1
cpe:/o:opensuse:opensuse:11.1

© SecPod Technologies