More kernel vulnerabilities - upgrade! [merged]

Updated kernel packages that fix security vulnerabilities which may allow
local users to gain root privileges are now available. These packages also
resolve other minor issues.


The Linux kernel handles the basic functions of the operating system.

Paul Starzetz discovered a flaw in return value checking in mremap() in the
Linux kernel versions 2.4.24 and previous that may allow a local attacker
to gain root privileges. No exploit is currently available; however this
issue is exploitable. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0077 to this issue.

The Vicam USB driver in kernel versions prior to 2.4.25 does not use the
copy_from_user function to access userspace, which crosses security
boundaries. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0075 to this issue.

Arjan van de Ven discovered a flaw in ncp_lookup() in ncpfs that could
allow local privilege escalation. ncpfs is only used to allow a system to
mount volumes of NetWare servers or print to NetWare printers. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0010 to this issue.

Alan Cox found issues in the R128 Direct Render Infrastructure that could
allow local privilege escalation. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0003 to this issue.
Direct links to RedHat9 packages:

i386:
ftp://updates.redhat.com/9/en/os/i38...-30.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i38...-30.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i38...-30.9.i386.rpm
ftp://updates.redhat.com/9/en/os/i38...-30.9.i386.rpm

i686:
ftp://updates.redhat.com/9/en/os/i68...-30.9.i686.rpm
ftp://updates.redhat.com/9/en/os/i68...-30.9.i686.rpm
ftp://updates.redhat.com/9/en/os/i68...-30.9.i686.rpm

 

 

 

 

Top