Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.56182
Categoría:Mandrake Local Security Checks
Título:Mandrake Security Advisory MDKSA-2006:018 (kernel)
Resumen:NOSUMMARY
Descripción:Description:

The remote host is missing an update to kernel
announced via advisory MDKSA-2006:018.

A number of vulnerabilites have been corrected in the Linux kernel:

A race condition in the 2.6 kernel could allow a local user to cause a
DoS by triggering a core dump in one thread while another thread has a
pending SIGSTOP (CVE-2005-3527).

The ptrace functionality in 2.6 kernels prior to 2.6.14.2, using
CLONE_THREAD, does not use the thread group ID to check whether it is
attaching to itself, which could allow local users to cause a DoS
(CVE-2005-3783).

The auto-reap child process in 2.6 kernels prior to 2.6.15 include
processes with ptrace attached, which leads to a dangling ptrace
reference and allows local users to cause a crash (CVE-2005-3784).

A locking problem in the POSIX timer cleanup handling on exit on
kernels 2.6.10 to 2.6.14 when running on SMP systems, allows a local
user to cause a deadlock involving process CPU timers (CVE-2005-3805).

The IPv6 flowlabel handling code in 2.4 and 2.6 kernels prior to
2.4.32 and 2.6.14 modifes the wrong variable in certain circumstances,
which allows local users to corrupt kernel memory or cause a crash by
triggering a free of non-allocated memory (CVE-2005-3806).

An integer overflow in 2.6.14 and earlier could allow a local user to
cause a hang via 64-bit mmap calls that are not properly handled on a
32-bit system (CVE-2005-3808).

As well, other bugfixes are included in this update:

Fixes to swsup and HDA sound fixes (DMA buffer fixes, and fixes for the
AD1986a codec, added support for Nvidia chipsets, and new model
information for the Gigabyte K8N51).

MCP51 forcedeth support has been added.

Affected: 2006.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

https://secure1.securityspace.com/smysecure/catid.html?in=MDKSA-2006:018

Risk factor : High

CVSS Score:
6.6

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2005-3527
BugTraq ID: 15723
http://www.securityfocus.com/bid/15723
http://www.securityfocus.com/archive/1/427981/100/0/threaded
http://www.mandriva.com/security/advisories?name=MDKSA-2006:018
http://secunia.com/advisories/17917
http://secunia.com/advisories/17918
SuSE Security Announcement: SUSE-SA:2005:067 (Google Search)
http://www.securityfocus.com/advisories/9806
SuSE Security Announcement: SUSE-SA:2005:068 (Google Search)
http://www.securityfocus.com/archive/1/419522/100/0/threaded
Common Vulnerability Exposure (CVE) ID: CVE-2005-3783
BugTraq ID: 15642
http://www.securityfocus.com/bid/15642
Debian Security Information: DSA-1017 (Google Search)
http://www.debian.org/security/2006/dsa-1017
Debian Security Information: DSA-1018 (Google Search)
http://www.debian.org/security/2006/dsa-1018
http://www.mandriva.com/security/advisories?name=MDKSA-2006:072
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174075
http://secunia.com/advisories/17761
http://secunia.com/advisories/17787
http://secunia.com/advisories/18203
http://secunia.com/advisories/19369
http://secunia.com/advisories/19374
http://secunia.com/advisories/19607
SGI Security Advisory: 20060402-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060402-01-U
https://usn.ubuntu.com/231-1/
Common Vulnerability Exposure (CVE) ID: CVE-2005-3784
BugTraq ID: 15625
http://www.securityfocus.com/bid/15625
Bugtraq: 20060706 Re: [ MDKSA-2006:116 ] - Updated kernel packages fixes multiple vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/439623/100/100/threaded
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174078
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9080
http://www.redhat.com/support/errata/RHSA-2006-0101.html
http://secunia.com/advisories/17786
http://secunia.com/advisories/18510
http://www.trustix.org/errata/2005/0070
http://www.vupen.com/english/advisories/2005/2649
Common Vulnerability Exposure (CVE) ID: CVE-2005-3805
BugTraq ID: 15722
http://www.securityfocus.com/bid/15722
Common Vulnerability Exposure (CVE) ID: CVE-2005-3806
BugTraq ID: 15729
http://www.securityfocus.com/bid/15729
http://www.securityfocus.com/archive/1/428028/100/0/threaded
http://www.securityfocus.com/archive/1/428058/100/0/threaded
http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:044
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9903
http://www.redhat.com/support/errata/RHSA-2006-0140.html
http://www.redhat.com/support/errata/RHSA-2006-0190.html
http://www.redhat.com/support/errata/RHSA-2006-0191.html
http://secunia.com/advisories/18562
http://secunia.com/advisories/18684
http://secunia.com/advisories/18977
Common Vulnerability Exposure (CVE) ID: CVE-2005-3808
BugTraq ID: 15846
http://www.securityfocus.com/bid/15846
http://www.securityfocus.com/advisories/9852
http://seclists.org/lists/linux-kernel/2005/Nov/7839.html
http://secunia.com/advisories/18788
http://secunia.com/advisories/19038
SuSE Security Announcement: SUSE-SA:2006:006 (Google Search)
http://www.novell.com/linux/security/advisories/2006_06_kernel.html
SuSE Security Announcement: SUSE-SA:2006:012 (Google Search)
http://lists.suse.de/archive/suse-security-announce/2006-Feb/0010.html
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.