[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:329 -- Mandriva kernel

ID: oval:org.secpod.oval:def:300668Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




Some vulnerabilities were discovered and corrected in the Linux 2.6 kernel: Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddpN device is not found, allows remote attackers to cause a denial of service via IP-DDP datagrams. Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname. The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881. net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket. Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function. The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state. The ip_frag_reasm function in ipv4/ip_fragment.c in Linux kernel 2.6.32-rc8, and possibly earlier versions, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service via long IP packets, possibly related to the ip_defrag function

Platform:
Mandriva Linux 2010.0
Mandriva Linux 2009.1
Product:
kernel
Reference:
MDVSA-2009:329
CVE-2009-4131
CVE-2009-1298
CVE-2009-3726
CVE-2009-3638
CVE-2009-3621
CVE-2009-3612
CVE-2009-3547
CVE-2009-2903
CVE    8
CVE-2009-1298
CVE-2009-3621
CVE-2009-3612
CVE-2009-2903
...
CPE    2
cpe:/o:mandriva:linux:2009.1
cpe:/o:mandriva:linux:2010.0

© SecPod Technologies