RHEL 4 : kernel (RHSA-2005:808)

This script is Copyright (C) 2005-2014 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing one or more security updates.

Description :

Updated kernel packages that fix several security issues and a page
attribute mapping bug are now available for Red Hat Enterprise Linux
4.

This update has been rated as having important security impact by the
Red Hat Security Response Team.

The Linux kernel handles the basic functions of the operating system.

An issue was discovered that affects how page attributes are changed
by the kernel. Video drivers, which sometimes map kernel pages with a
different caching policy than write-back, are now expected to function
correctly. This change affects the x86, AMD64, and Intel EM64T
architectures.

In addition the following security bugs were fixed :

The set_mempolicy system call did not check for negative numbers in
the policy field. An unprivileged local user could use this flaw to
cause a denial of service (system panic). (CVE-2005-3053)

A flaw in ioremap handling on AMD 64 and Intel EM64T systems. An
unprivileged local user could use this flaw to cause a denial of
service or minor information leak. (CVE-2005-3108)

A race condition in the ebtables netfilter module. On a SMP system
that is operating under a heavy load this flaw may allow remote
attackers to cause a denial of service (crash). (CVE-2005-3110)

A memory leak was found in key handling. An unprivileged local user
could use this flaw to cause a denial of service. (CVE-2005-3119)

A flaw in the Orinoco wireless driver. On systems running the
vulnerable drive, a remote attacker could send carefully crafted
packets which would divulge the contents of uninitialized kernel
memory. (CVE-2005-3180)

A memory leak was found in the audit system. An unprivileged local
user could use this flaw to cause a denial of service. (CVE-2005-3181)

All Red Hat Enterprise Linux 4 users are advised to upgrade their
kernels to the packages associated with their machine architectures
and configurations as listed in this erratum.

See also :

https://www.redhat.com/security/data/cve/CVE-2005-3053.html
https://www.redhat.com/security/data/cve/CVE-2005-3108.html
https://www.redhat.com/security/data/cve/CVE-2005-3110.html
https://www.redhat.com/security/data/cve/CVE-2005-3119.html
https://www.redhat.com/security/data/cve/CVE-2005-3180.html
https://www.redhat.com/security/data/cve/CVE-2005-3181.html
http://rhn.redhat.com/errata/RHSA-2005-808.html

Solution :

Update the affected packages.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)

Family: Red Hat Local Security Checks

Nessus Plugin ID: 20104 ()

Bugtraq ID:

CVE ID: CVE-2005-3053
CVE-2005-3108
CVE-2005-3110
CVE-2005-3119
CVE-2005-3180
CVE-2005-3181