Users of kernel please be advised of a buffer-overflow, race condition, denial-of-service Vulnerabilities that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)
Amplify’d from www.criticalwatch.com
RHSA-2010:0907-01: [RHSA-2010:0907-01] kernel buffer-overflow, race condition, denial-of-service
Product: Red Hat Enterprise Linux
Summary:
Updated kernel packages that fix one security issue and four bugs are nowavailable for Red Hat Enterprise Linux 5.4 Extended Update Support.
Description:
The kernel packages contain the Linux kernel, the core of any Linuxoperating system.This update fixes the following security issue:
* Buffer overflow flaws were found in the Linux kernel's implementation of
the server-side External Data Representation (XDR) for the Network File
System (NFS) version 4. An attacker on the local network could send a
specially-crafted large compound request to the NFSv4 server, which could
possibly result in a kernel panic (denial of service) or, potentially, codeexecution. (CVE-2010-2521, Important)
* A race condition existed when generating new process IDs with the resultRead more at www.criticalwatch.com
that the wrong process could have been signaled or killed accidentally,
leading to various application faults. This update detects and disallowsthe reuse of PID numbers. (BZ#638865)
See this Amp at http://bit.ly/ePWNyK

No comments:
Post a Comment