Solutions de vulnérabilité

L'analyse périodique de vulnérabilité Nimsoft Cloud Monitor vérifie la vulnérabilité ci-dessous. Pour connaître les solutions de vulnérabilité les plus récemment ajoutées analysées par WatchMouse, rendez-vous sur la vue d'ensemble Solutions de vulnérabilité

Catégorie: Ubuntu Local Security Checks Facteur de risque: Medium Ajouté: 18 mars 2010
Synopsis:

These remote packages are missing security patches : - linux-doc
- linux-doc-2.6.15 - linux-doc-2.6.24
- linux-doc-2.6.27 - linux-doc-2.6.28
- linux-ec2-doc
- linux-ec2-source-2.6.31 - linux-headers-2.6.15-55
- linux-headers-2.6.15-55-386 - linux-headers-2.6.15-55-686
- linux-headers-2.6.15-55-amd64-generic - linux-headers-2.6.15-55-amd64-k8 - linux-headers-2.6.15-55-amd64-server - linux-headers-2.6.15-55-amd64-xeon - linux-headers-2.6.15-55-k7
- linux-headers-2.6.15-55-powerpc - linux-head
[...]

Description:

Mathias Krause discovered that the Linux kernel did not correctly handle missing ELF interpreters. A local attacker could exploit this to cause the system to crash, leading to a denial of service. (CVE-2010-0307)

Marcelo Tosatti discovered that the Linux kernel's hardware virtualization did not correctly handle reading the /dev/port special device. A local attacker in a guest operating system could issue a specific read that would cause the host system to crash, leading to a denial of service. (CVE-2010-0309)

Sebastian Krahmer discovered that the Linux kernel did not correctly handle netlink connector messages. A local attacker could exploit this to consume kernel memory, leading to a denial of service. (CVE-2010-0410)

Ramon de Carvalho Valle discovered that the Linux kernel did not correctly validate certain memory migration calls. A local attacker could exploit this to read arbitrary kernel memory or cause a system crash, leading to a denial of service. (CVE-2010-0415)

Jermome Marchand and Mikael
[...]

Solution:

Upgrade to :
- linux-doc-2.6.31-20.58 (Ubuntu 9.10) - linux-doc-2.6.15-2.6.15-55.83 (Ubuntu 6.06) - linux-doc-2.6.24-2.6.24-27.68 (Ubuntu 8.04) - linux-doc-2.6.27-2.6.27-17.46 (Ubuntu 8.10) - linux-doc-2.6.28-2.6.28-18.60 (Ubuntu 9.04) - linux-ec2-doc-2.6.31-305.13 (Ubuntu 9.10) - linux-ec2-source-2.6.31-2.6.31-305.13 (Ubuntu 9.10) - linux-headers-2.6.15-55-2.6.15-55.83 (Ubuntu 6.06) - linux-headers-2.6.15-55-386-2.6.15-55.83 (Ubuntu 6.06) - linux-headers-2.6.15-55-686-2.6.15-55.83 (Ubuntu 6.06)
- linux-h
[...]

Risk factor:

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C)