[CLA-2004:799] Conectiva Security Announcement - kernel

From: Conectiva Updates (secure_at_conectiva.com.br)
Date: 01/05/04

  • Next message: Martin Schulze: "[SECURITY] [DSA 407-1] New ethereal packages fix several vulnerabilities"
    Date: Mon, 5 Jan 2004 13:46:45 -0200
    To: conectiva-updates@papaleguas.conectiva.com.br, lwn@lwn.net, bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linsec@lists.seifried.org
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - --------------------------------------------------------------------------
    CONECTIVA LINUX SECURITY ANNOUNCEMENT
    - --------------------------------------------------------------------------

    PACKAGE : kernel
    SUMMARY : Fix for two vulnerabilities
    DATE : 2004-01-05 13:46:00
    ID : CLA-2004:799
    RELEVANT
    RELEASES : 8, 9

    - -------------------------------------------------------------------------

    DESCRIPTION
     The Linux kernel is responsible for handling the basic functions of
     the GNU/Linux operating system.
     
     This announcement fixes two local vulnerabilities in the kernel
     package:
     
     1) mremap() local vulnerability (CAN-2003-0985[2])
     Paul Starzetz <ihaquer@isec.pl> from iSEC Security Research
     reported[1] another vulnerability in the Linux memory management code
     which can be used by local attackers to obtain root privileges or
     cause a denial of service condition (DoS).
     
     2) Information leak in RTC code (CAN-2003-0984[3])
     Russell King <rmk@arm.linux.org.uk> reported that real time clock
     (RTC) routines in Linux kernel 2.4.23 and earlier do not properly
     initialize their structures, which could leak kernel data to user
     space.

    SOLUTION
     It is recommended that all Conectiva Linux users upgrade the kernel
     package.
     
     IMPORTANT: exercise caution and preparation when upgrading the
     kernel, since it will require a reboot after the new packages are
     installed. In particular, Conectiva Linux 9 will most likely require
     an initrd file (which is automatically created in the /boot directory
     after the new packages are installed). Generic kernel update
     instructions can be obtained in the manuals and in our faq page[4].
     
     
     REFERENCES
     1.http://isec.pl/vulnerabilities/isec-0013-mremap.txt
     2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0985
     3.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0984
     4.http://www.conectiva.com.br/suporte/pr/sistema.kernel.atualizar.html

    UPDATED PACKAGES
    ftp://atualizacoes.conectiva.com.br/8/SRPMS/kernel-2.4.19-1U80_20cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/devfsd-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-2.4.19-1U80_20cl.i586.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-2.4.19-1U80_20cl.i686.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-BOOT-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-doc-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-enterprise-2.4.19-1U80_20cl.i686.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-headers-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-rbc-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-smp-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-smp-2.4.19-1U80_20cl.i586.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-smp-2.4.19-1U80_20cl.i686.rpm
    ftp://atualizacoes.conectiva.com.br/8/RPMS/kernel-source-2.4.19-1U80_20cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/SRPMS/kernel24-2.4.21-31301U90_13cl.src.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/devfsd-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-2.4.21-31301U90_13cl.athlon.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-2.4.21-31301U90_13cl.i586.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-2.4.21-31301U90_13cl.i686.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-2.4.21-31301U90_13cl.pentium4.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-BOOT-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-doc-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-enterprise-2.4.21-31301U90_13cl.athlon.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-enterprise-2.4.21-31301U90_13cl.i686.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-enterprise-2.4.21-31301U90_13cl.pentium4.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-rbc-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-headers-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-smp-2.4.21-31301U90_13cl.athlon.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-smp-2.4.21-31301U90_13cl.i386.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-smp-2.4.21-31301U90_13cl.i586.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-smp-2.4.21-31301U90_13cl.i686.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-smp-2.4.21-31301U90_13cl.pentium4.rpm
    ftp://atualizacoes.conectiva.com.br/9/RPMS/kernel24-source-2.4.21-31301U90_13cl.i386.rpm

    ADDITIONAL INSTRUCTIONS
     The apt tool can be used to perform RPM packages upgrades:

     - run: apt-get update
     - after that, execute: apt-get upgrade

     Detailed instructions reagarding the use of apt and upgrade examples
     can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en

    - -------------------------------------------------------------------------
    All packages are signed with Conectiva's GPG key. The key and instructions
    on how to import it can be found at
    http://distro.conectiva.com.br/seguranca/chave/?idioma=en
    Instructions on how to check the signatures of the RPM packages can be
    found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en

    - -------------------------------------------------------------------------
    All our advisories and generic update instructions can be viewed at
    http://distro.conectiva.com.br/atualizacoes/?idioma=en

    - -------------------------------------------------------------------------
    Copyright (c) 2003 Conectiva Inc.
    http://www.conectiva.com

    - -------------------------------------------------------------------------
    subscribe: conectiva-updates-subscribe@papaleguas.conectiva.com.br
    unsubscribe: conectiva-updates-unsubscribe@papaleguas.conectiva.com.br
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (GNU/Linux)
    Comment: For info see http://www.gnupg.org

    iD8DBQE/+Ybk42jd0JmAcZARAlJKAJ9x6rYu5qb5jtj4LcLlOiujzTQW/ACgvvTj
    uK6MQOfSZS/wH32ltbNIXt0=
    =ZgeM
    -----END PGP SIGNATURE-----


  • Next message: Martin Schulze: "[SECURITY] [DSA 407-1] New ethereal packages fix several vulnerabilities"

    Relevant Pages

    • [CLA-2003:747] Conectiva Security Announcement - kde
      ... CONECTIVA LINUX SECURITY ANNOUNCEMENT ... PACKAGE: kde ... This update includes fixes for several vulnerabilities in the KDE ... Please note that the KDE packages for Conectiva Linux 8 are being ...
      (Bugtraq)
    • [CLA-2003:701] Conectiva Security Announcement - kernel
      ... Vulnerabilities and bugfixes for the kernel ... This update for Conectiva Linux 9 addresses several issues which are ... Al Viro found a vulnerability in the TTY layer where a local attacker ... The kernel packages have been fixed to allow the correct compilation ...
      (Bugtraq)
    • [FLSA-2004:1804] Updated kernel resolves security vulnerabilities
      ... Updated kernel packages that fix security vulnerabilities which may ... allow local users to gain root privileges are now available. ... The Linux kernel handles the basic functions of the operating system. ... Vulnerabilities and Exposures project has assigned the name ...
      (Bugtraq)
    • [Full-Disclosure] [FLSA-2004:1804] Updated kernel resolves security vulnerabilities
      ... Updated kernel packages that fix security vulnerabilities which may ... allow local users to gain root privileges are now available. ... The Linux kernel handles the basic functions of the operating system. ... Vulnerabilities and Exposures project has assigned the name ...
      (Full-Disclosure)
    • [FLSA-2004:1804] Updated kernel resolves security vulnerabilities
      ... Updated kernel packages that fix security vulnerabilities which may ... allow local users to gain root privileges are now available. ... The Linux kernel handles the basic functions of the operating system. ... Vulnerabilities and Exposures project has assigned the name ...
      (Full-Disclosure)