Vendor Status Note JVNCIAC-R-117

Linux のカーネルに複数の脆弱性

概要

Red Hat Enterprise Linux にて標準で提供されている Linux のカーネルには、複数の脆弱性があります。

想定される影響

ローカルユーザが任意のコードを実行したり、サービス運用妨害 (DoS) 攻撃を行ったりする可能性があります。

ベンダ情報

ベンダリンク更新日
DebianDebian Security Advisory DSA-1233
kernel-source-2.6.8 -- several vulnerabilities
Debian Security Advisory DSA-1237
kernel-source-2.4.27 -- several vulnerabilities
Red HatRed Hat Security Advisory RHSA-2007:0014
Important: kernel security update
参考情報

  1. ISS X-Force Database: kernel-ia64-sparc-elf-dos(29007)
    Linux kernel IA64 and SPARC ELF denial of service
  2. ISS X-Force Database: linux-mincore-dos(30999)
    Linux kernel mincore() function denial of service
  3. ISS X-Force Database: kernel-copyfromuser-information-disclosure(29378)
    Linux kernel copy_from_User information disclosure
  4. ISS X-Force Database: kernel-seqfile-ipv6-dos(29970)
    Linux Kernel seqfile IPv6 flowlabel denial of service
  5. ISS X-Force Database: linux-getfdbentries-integer-overflow(30588)
    Linux kernel get_fdb_entries() function integer overflow
  6. ISS X-Force Database: kernel-listxattr-dos(32008)
    Linux kernel listxattr denial of service
  7. ISS X-Force Database: kernel-iso9660-dos(30029)
    Linux kernel ISO9660 denial of service
  8. ISS X-Force Database: linux-zlibinflate-dos(30154)
    Linux kernel zlib_inflate() denial of service
  9. ISS X-Force Database: kernel-ext3fsdirhash-dos(30217)
    Linux kernel ext3fs_dirhash() denial of service
  10. ISS X-Force Database: kernel-ext2-filesystem-dos(30201)
    Linux kernel ext2 filesystem denial of service
  11. ISS X-Force Database: linux-superblockdoinit-dos(30278)
    Linux kernel superblock_doinit denial of service
  12. ISS X-Force Database: kernel-cmtprecvinteropmsg-bo(30912)
    Linux kernel cmtp_recv_interopmsg() buffer overflow

JPCERT 緊急報告
JPCERT REPORTJPCERT-WR-2007-0502 ( 2007-02-07 )
CIAC BulletinR-117 Kernel Security Update ( 2007-01-30 )
CVE2006-4538 [CVE+] XF29007
2006-4813 [CVE+]
2006-4814 [CVE+] XF30999
2006-5174 [CVE+] XF29378
2006-5619 [CVE+] XF29970
2006-5751 [CVE+] XF30588
2006-5753 [CVE+] XF32008
2006-5754 [CVE+]
2006-5757 [CVE+] XF30029
2006-5823 [CVE+] XF30154
2006-6053 [CVE+] XF30217
2006-6054 [CVE+] XF30201
2006-6056 [CVE+] XF30278
2006-6106 [CVE+] XF30912
2006-6535 [CVE+]
PGP署名JVNCIAC-R-117.html.sig

登録日11:46 2007/02/10
更新日11:46 2007/02/10

Copyright(C) 2002-2009 Keio Univ. All rights reserved.