U radu jezgre operacijskog sustava otkriveno je nekoliko propusta koje mogu iskoristiti lokalni ili udaljeni korisnici u svrhu izvođenja DoS napada, povećanje ovlasti ili otkrivanja osjetljivih informacija.
Većina propusta je vezana uz nepravilno rukovanje memorijom poput pogrešaka u funkcijama "ib_uverbs_poll_cq()", "agp_allocate_memory()" i "ib_uverbs_poll_cq()", a mogu uzrokovati cjelobrojno prepisivanje i preljev međuspremnika.
Posljedica:
Većina propusta se može iskoristiti lokalno za izvođenje DoS napada i povećanje privilegija, te otkrivanje osjetljivih informacija. Udaljeni napadači mogu iskoristiti propuste i za DoS napad.
Rješenje:
Kako bi se zaštitili, korisnicima se savjetuje žurna primjena nadogradnje.
CentOS Errata and Security Advisory 2011:0927 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-0927.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
i386:
40261f41e17f5847e5542f21a901bd89 kernel-2.6.18-238.19.1.el5.i686.rpm
ea0ede2d0ad22c8214ee16d953d5d6d2 kernel-debug-2.6.18-238.19.1.el5.i686.rpm
deec5173a7ef557929db5fda3463b51e
kernel-debug-devel-2.6.18-238.19.1.el5.i686.rpm
cc8279cf9d118c6203240d7f98f26778 kernel-devel-2.6.18-238.19.1.el5.i686.rpm
e2350bff673fc28f02e37a05a96067a3 kernel-doc-2.6.18-238.19.1.el5.noarch.rpm
68241e041732ffd7847a931527edea65 kernel-headers-2.6.18-238.19.1.el5.i386.rpm
958e828c2080f2ef79ac203f6bcf09a9 kernel-PAE-2.6.18-238.19.1.el5.i686.rpm
80d97b2f0d78b66dbdcbed765395eeaf
kernel-PAE-devel-2.6.18-238.19.1.el5.i686.rpm
8c4629ee49f39a3e3721f1e09e77a69a kernel-xen-2.6.18-238.19.1.el5.i686.rpm
d93b4d38af1fab0a959a870d42838680
kernel-xen-devel-2.6.18-238.19.1.el5.i686.rpm
Source:
7bc7a9f7b653216b34542ff733f7abf1 kernel-2.6.18-238.19.1.el5.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2011:0927 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2011-0927.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( md5sum Filename )
x86_64:
7ad0a67c4f4c28003fff543c9b015898 kernel-2.6.18-238.19.1.el5.x86_64.rpm
45307a106fd29f07c4f590156cfdf207 kernel-debug-2.6.18-238.19.1.el5.x86_64.rpm
0d6d847a4bea5c34b9486013ffcc6b99
kernel-debug-devel-2.6.18-238.19.1.el5.x86_64.rpm
5c8883d6c06de9380eb6471ce536bae9 kernel-devel-2.6.18-238.19.1.el5.x86_64.rpm
c72015ce88ebf092685b6e41316d8a56 kernel-doc-2.6.18-238.19.1.el5.noarch.rpm
0bf8bdcc7ad8aa82c819dfafef4517e5
kernel-headers-2.6.18-238.19.1.el5.x86_64.rpm
f14c3863855aad4d6ca0ddd9244eed70 kernel-xen-2.6.18-238.19.1.el5.x86_64.rpm
8dfd9cc91f7db06c3872d40902b88503
kernel-xen-devel-2.6.18-238.19.1.el5.x86_64.rpm
Source:
7bc7a9f7b653216b34542ff733f7abf1 kernel-2.6.18-238.19.1.el5.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke