Vendor Status Note JVNCIAC-P-047

Red Hat Linux Kernel に複数の脆弱性

概要

Red Hat Linux のカーネルには、バッファオーバーフローなど複数の脆弱性があります。

想定される影響

ローカルユーザが root 権限を取得する可能性があります。

ベンダ情報

ベンダリンク更新日
RedHatRedHat Advisory RHSA-2004:549
Updated kernel packages fix security vulnerabilities
Turbolinux JapanTurbolinux Security Advisory TLSA-2004-34
セキュリティとバグフィックス
Vine Linuxkernel にセキュリティホール
参考情報

  1. US-CERT Vulnerability Note VU#981134
    Linux kernel USB drivers do not initialize kernel memory properly
  2. ISS X-Force Database: irix-mapelf32exec-dos(16416)
    SGI IRIX mapelf32exec denial of service
  3. ISS X-Force Database: bcm5820-adddsabufbytes-integer-bo(16495)
    Broadcom 5820 Cryptonet Driver add_dsa_buf_bytes integer overflow
  4. ISS X-Force Database: linux-usb-gain-privileges(16931)
    Linux Kernel USB allows elevated privileges
  5. ISS X-Force Database: linux-tss-gain-privilege(18346)
    Linux kernel TSS gain privilege
  6. ISS X-Force Database: linux-smb-response-dos(18134)
    Linux kernel SMB response denial of service
  7. ISS X-Force Database: linux-smbprocreadxdata-dos(18135)
    Linux kernel smb_proc_readX_data denial of service
  8. ISS X-Force Database: linux-smbreceivetrans2-dos(18136)
    Linux kernel smb_receive_trans2 denial of service
  9. ISS X-Force Database: linux-smbrecvtrans2-memory-leak(18137)
    Linux kernel smb_recv_trans2 memory leak
  10. ISS X-Force Database: linux-afunix-race-condition(18230)
    Linux kernel AF_UNIX race condition
  11. ISS X-Force Database: linux-elf-setuid-gain-privileges(18025)
    Linux Kernel ELF setuid allows elevated privileges

JPCERT 緊急報告
JPCERT REPORTJPCERT-WR-2004-4801 ( 2004-12-08 )
JPCERT-WR-2005-0101 ( 2005-01-06 )
CIAC BulletinP-047 Red Hat Updated Kernel Packages ( 2004-12-02 )
CVE2004-0136 [CVE+] XF16416
2004-0619 [CVE+] XF16495
2004-0685 [CVE+] VU#981134,XF16931
2004-0812 [CVE+] XF18346
2004-0883 [CVE+] XF18134,XF18135,XF18136
2004-0949 [CVE+] XF18137
2004-1068 [CVE+] XF18230
2004-1070 [CVE+] XF18025
2004-1071 [CVE+] XF18025
2004-1072 [CVE+] XF18025
2004-1073 [CVE+] XF18025
PGP署名JVNCIAC-P-047.html.sig

登録日11:39 2004/12/12
更新日13:43 2005/01/09

Copyright(C) 2002-2009 Keio Univ. All rights reserved.