Paketname
kernel
Datum
2010-02-18
Advisory ID
MDVSA-2010:034-2
Betroffene Versionen
MES5 x86_64

Problembeschreibung

Some vulnerabilities were discovered and corrected in the Linux
2.6 kernel:

Array index error in the gdth_read_event function in
drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows
local users to cause a denial of service or possibly gain privileges
via a negative event index in an IOCTL request. (CVE-2009-3080)

The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the
Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified
impact via a crafted HDLC packet that arrives over ISDN and triggers
a buffer under-read. (CVE-2009-4005)

Additionally, the Linux kernel was updated to the stable release
2.6.27.45.

To update your kernel, please follow the directions located at:

http://www.mandriva.com/en/security/kernelupdate

Update:

The nvidia173-kernel x86_64 packages was missing with MDVSA-2010:034
for the Enterprise 5 product. This advisory provides the missing
packages.

Aktualisierte Pakete

MES5 x86_64

 0779d5654b351427c470e36ffe5248a4  mes5/x86_64/nvidia173-kernel-2.6.27.45-desktop-1mnb-173.14.12-4mdv2009.0.x86_64.rpm
 b22dbcfda9d8239460e9a27483e90067  mes5/x86_64/nvidia173-kernel-2.6.27.45-server-1mnb-173.14.12-4mdv2009.0.x86_64.rpm
 090ccae6731eedcc2aeef3bb6db41d3b  mes5/x86_64/nvidia173-kernel-desktop-latest-173.14.12-1.20100218.4mdv2009.0.x86_64.rpm
 0029c41881af4e801a4355533bc791ca  mes5/x86_64/nvidia173-kernel-server-latest-173.14.12-1.20100218.4mdv2009.0.x86_64.rpm

Referenzen