Voor de gegadigden, vond het wel de moeite waard om onder ogen te brengen.
http://secunia.com/product/2719/
Code:TITLE: Linux Kernel Multiple Vulnerabilities SECUNIA ADVISORY ID: SA14295 VERIFY ADVISORY: http://secunia.com/advisories/14295/ CRITICAL: Moderately critical IMPACT: Unknown, Security Bypass, Exposure of sensitive information, DoS WHERE: From remote OPERATING SYSTEM: Linux Kernel 2.6.x http://secunia.com/product/2719/ DESCRIPTION: Some vulnerabilities have been reported in the Linux kernel. These can be exploited by malicious, local users to gain knowledge of potentially sensitive information or cause a DoS (Denial of Service), or by malicious people to cause a DoS or bypass certain security restrictions. 1) Insufficient permission checking in the "shmctl()" function allows any process to lock/unlock arbitrary System V shared memory segments that fall within the RLIMIT_MEMLOCK limit. This can be exploited to unlock locked memory of other processes, which may result in sensitive information being written to swap space. 2) A race condition exists in the terminal handling of the "setsid()" function used for starting new process sessions. 3) Table sizes in "nls_ascii.c" are incorrectly set to 128 instead of 256, which may be exploited to cause buffer overflows and crash the kernel. 4) A design error in the netfilter/iptables module can be exploited to crash the kernel or bypass firewall rules via specially crafted packets. SOLUTION: 1-2) Secunia is currently not aware of an updated kernel version addressing the vulnerabilities. Grant only trusted users access to affected systems. 3) The vulnerability has been fixed in version 2.6.11-rc1. 4) The vulnerability has been fixed in version 2.6.11-rc3. PROVIDED AND/OR DISCOVERED BY: 1) Michael Kerrisk 3) Ogawa Hirofumi 4) David Coulson ORIGINAL ADVISORY: http://www.ubuntulinux.org/support/d...n/usn/usn-82-1 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=:) ----------------------------------------------------------------------

Likes:


Quote
