[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:118 -- Mandriva kernel

ID: oval:org.secpod.oval:def:301234Date: (C)2012-01-07   (M)2024-02-19
Class: PATCHFamily: unix




Some vulnerabilities were discovered and corrected in the Linux 2.6 kernel: The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit. fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service , or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index. The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle a 32-bit process making a 64-bit syscall or a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343. The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle a 32-bit process making a 64-bit syscall or a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as stat or chmod, a related issue to CVE-2009-0342 and CVE-2009-0343. The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the node and port, which allows local users to bypass intended restrictions on network traffic. NOTE: this was incorrectly reported as an issue fixed in 2.6.27.21. Additionally, along with other things, this kernel update adds support for D-Link DWM 652 3.5G, some Intel gigabit network chipsets, Avermedia PCI pure analog , fixes a bug causing SQLite performance regression, and has some updated ALSA drivers. Check the package changelog for details

Platform:
Mandriva Linux 2009.0
Product:
kernel
Reference:
MDVSA-2009:118
CVE-2009-1184
CVE-2009-0835
CVE-2009-0834
CVE-2009-0269
CVE-2009-0028
CVE    5
CVE-2009-0028
CVE-2009-0269
CVE-2009-0835
CVE-2009-0834
...
CPE    1
cpe:/o:mandriva:linux:2009.0

© SecPod Technologies