Mandriva Security http://www.mandriva.com/en/security/advisories Mandriva security advisories en-us MDVA-2010:054: cacti http://www.mandriva.com/en/security/advisories?name=MDVA-2010:054 This update fixes several bugs in existing package:<br /> - fix rights on configuration file<br /> - fix path for logs<br /> - fix path for rra files<br /> - add new version for rrdtools in cacti wizard MDVSA-2010:034: kernel http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:034 Some vulnerabilities were discovered and corrected in the Linux<br /> 2.6 kernel:<br /> <br /> Array index error in the gdth_read_event function in<br /> drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows<br /> local users to cause a denial of service or possibly gain privileges<br /> via a negative event index in an IOCTL request. (CVE-2009-3080)<br /> <br /> The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the<br /> Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified<br /> impact via a crafted HDLC packet that arrives over ISDN and triggers<br /> a buffer under-read. (CVE-2009-4005)<br /> <br /> Additionally, the Linux kernel was updated to the stable release<br /> 2.6.27.45.<br /> <br /> To update your kernel, please follow the directions located at:<br /> <br /> http://www.mandriva.com/en/security/kernelupdate MDVA-2010:053: mmc-wizard http://www.mandriva.com/en/security/advisories?name=MDVA-2010:053 Remove 64bit templates as mmc packages are noarch now. The updated<br /> packages have been patched to correct this issue. MDVA-2010:052: microcode_ctl http://www.mandriva.com/en/security/advisories?name=MDVA-2010:052 microcode_ctl is now providing a script to allow updates to retreive<br /> the latest versions of microcodes. MDVA-2010:051: mmc-web-base http://www.mandriva.com/en/security/advisories?name=MDVA-2010:051 This update removes the disclaimer which incorrectly appears on<br /> initial MMC web page. MDVA-2010:050: mmc-agent http://www.mandriva.com/en/security/advisories?name=MDVA-2010:050 MMC web interface allows to create isos for user's homes and<br /> shares. With this update, mkisofs has been added as a requirement of<br /> the package. MDVSA-2010:033: squid http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:033 A vulnerability have been discovered and corrected in Squid 2.x,<br /> 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15, which allows<br /> remote attackers to cause a denial of service (assertion failure)<br /> via a crafted DNS packet that only contains a header (CVE-2010-0308).<br /> <br /> This update provides a fix to this vulnerability. MDVSA-2010:032: rootcerts http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:032 It was brought to our attention by Ludwig Nussel at SUSE the md5<br /> collision certificate should not be included. This update removes<br /> the offending certificate.<br /> <br /> Packages for 2008.0 are provided for Corporate Desktop 2008.0<br /> customers.<br /> <br /> The mozilla nss library has consequently been rebuilt to pickup these<br /> changes and are also being provided. MDVSA-2010:031: wireshark http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:031 This advisory updates Wireshark to the version 1.0.11, which fixes<br /> the following vulnerabilities:<br /> <br /> The SMB and SMB2 dissectors could crash (CVE-2009-4377).<br /> The Infiniband dissector could crash on some platforms (CVE-2009-2563).<br /> Several buffer overflows were discovered and fixed in the LWRES<br /> dissector. MDVSA-2010:030: kernel http://www.mandriva.com/en/security/advisories?name=MDVSA-2010:030 Some vulnerabilities were discovered and corrected in the Linux<br /> 2.6 kernel:<br /> <br /> Array index error in the gdth_read_event function in<br /> drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows<br /> local users to cause a denial of service or possibly gain privileges<br /> via a negative event index in an IOCTL request. (CVE-2009-3080)<br /> <br /> The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the<br /> Linux kernel before 2.6.32-rc7 allows attackers to have an unspecified<br /> impact via a crafted HDLC packet that arrives over ISDN and triggers<br /> a buffer under-read. (CVE-2009-4005)<br /> <br /> An issue was discovered in 2.6.32.x kernels, which sets unsecure<br /> permission for devtmpfs file system by default. (CVE-2010-0299)<br /> <br /> Additionally, it was added support for Atheros AR2427 Wireless<br /> Network Adapter.<br /> <br /> To update your kernel, please follow the directions located at:<br /> <br /> http://www.mandriva.com/en/security/kernelupdate