Ubuntu 8.04 LTS : linux vulnerabilities (USN-614-1)

Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

It was discovered that PowerPC kernels did not correctly handle
reporting certain system details. By requesting a specific set of
information, a local attacker could cause a system crash resulting in
a denial of service. (CVE-2007-6694)

A race condition was discovered between dnotify fcntl() and close() in
the kernel. If a local attacker performed malicious dnotify requests,
they could cause memory consumption leading to a denial of service, or
possibly send arbitrary signals to any process. (CVE-2008-1375)

On SMP systems, a race condition existed in fcntl(). Local attackers
could perform malicious locks, causing system crashes and leading to a
denial of service. (CVE-2008-1669)

The tehuti network driver did not correctly handle certain IO
functions. A local attacker could perform malicious requests to the
driver, potentially accessing kernel memory, leading to privilege
escalation or access to private system information. (CVE-2008-1675).

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.8

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 33093 ()

Bugtraq ID:

CVE ID: CVE-2007-6694