diff options
author | dann frazier <dannf@debian.org> | 2007-04-09 18:19:03 +0000 |
---|---|---|
committer | dann frazier <dannf@debian.org> | 2007-04-09 18:19:03 +0000 |
commit | 70e4705ae506478fd48115bb713dfe0c339c938f (patch) | |
tree | 449d2f5987a252ac23baacc7766d0391a7642d41 | |
parent | 0b8b72b27eb2fa593f361c3854ce2cda376f3344 (diff) |
start dsa text for 2.6.18.dfsg.1-12etch1
git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@741 e094ebfe-e918-0410-adfb-c712417f3574
-rw-r--r-- | dsa-texts/2.6.18.dfsg.1-12etch1 | 87 |
1 files changed, 87 insertions, 0 deletions
diff --git a/dsa-texts/2.6.18.dfsg.1-12etch1 b/dsa-texts/2.6.18.dfsg.1-12etch1 new file mode 100644 index 00000000..251de9a9 --- /dev/null +++ b/dsa-texts/2.6.18.dfsg.1-12etch1 @@ -0,0 +1,87 @@ +-------------------------------------------------------------------------- +Debian Security Advisory DSA XXX-1 security@debian.org +http://www.debian.org/security/ Dann Frazier +XXXXX 8th, 2007 http://www.debian.org/security/faq +-------------------------------------------------------------------------- + +Package : linux-2.6 +Vulnerability : several +Problem-Type : local/remote +Debian-specific: no +CVE ID : CVE-2007-0005 CVE-2007-0958 CVE-2007-1357 CVE-2007-1592 + +Several local and remote vulnerabilities have been discovered in the Linux +kernel that may lead to a denial of service or the execution of arbitrary +code. The Common Vulnerabilities and Exposures project identifies the +following problems: + +CVE-2007-0005 + + Daniel Roethlisberger discovered two buffer overflows in the cm4040 + driver for the Omnikey CardMan 4040 device. A local user or malicious + device could exploit this to execute arbitrary code in kernel space. + +CVE-2007-0958 + + Santosh Eraniose reported a vulnerability that allows local users to read + otherwise unreadable files by triggering a core dump while using PT_INTERP. + This is related to CVE-2004-1073. + +CVE-2007-1357 + + Jean Delvare reported a vulnerability in the appletalk subsystem. + Systems with the appletalk module loaded can be triggered to crash + by other systems on the local network via a malformed frame. + +CVE-2007-1592 + + Masayuki Nakagawa discovered that flow labels were inadvertently + being shared between listening sockets and child sockets. This defect + can be exploited by local users to cause a DoS (Oops). + +This problem has been fixed in the stable distribution in version +2.6.18.dfsg.1-12etch1. + +The following matrix lists additional packages that were rebuilt for +compatibility with or to take advantage of this update: + + Debian 4.0 (etch) + fai-kernels <need binNMU> + user-mode-linux + +We recommend that you upgrade your kernel package immediately and reboot +the machine. If you have built a custom kernel from the kernel source +package, you will need to rebuild to take advantage of these fixes. + +Upgrade Instructions +-------------------- + +wget url + will fetch the file for you +dpkg -i file.deb + will install the referenced file. + +If you are using the apt-get package manager, use the line for +sources.list as given below: + +apt-get update + will update the internal database +apt-get upgrade + will install corrected packages + +You may use an automated update by adding the resources from the +footer to the proper configuration. + + +Debian GNU/Linux 4.0 alias etch +-------------------------------- + + + These files will probably be moved into the stable distribution on + its next update. + +--------------------------------------------------------------------------------- +For apt-get: deb http://security.debian.org/ etch/updates main +For dpkg-ftp: ftp://security.debian.org/debian-security dists/etch/updates/main +Mailing list: debian-security-announce@lists.debian.org +Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> |