Oplossingen voor kwetsbaarheid

De WatchMouse Periodieke Kwetsbaarheidscan controleert op onderstaande kwetsbaarheden. De meest recent toegevoegde oplossingen voor kwetsbaarheid die door WatchMouse worden gescand vindt u in het overzicht Oplossingen voor kwetsbaarheid

Categorie: SuSE Local Security Checks Risicofactor: High Toegevoegd: 4 Dec 2008
Synopsis:

The remote SuSE system is missing the security patch kernel-5734.

Description:

This patch updates the SUSE Linux Enterprise 10 SP1 kernel. It fixes various bugs and security issues.

Following security issues are addressed:

CVE-2008-4210: fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.

CVE-2008-3528: The ext[234] filesystem code fails to properly handle corrupted data structures. With a mounted filesystem image or partition that have corrupted
dir->i_size and dir->i_blocks, a user performing either a read or write operation on the mounted image or partition can lead to a possible denial of service by spamming the
logfile.

CVE-2007-6716: fs/direct-io.c in the dio subsystem in the Linux kernel did not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

All other bugfixes can be found by looking at the RPM
changelog.


Solution:

Install the security patch kernel-5734.

Risk factor:

High

Close
login