Oracle Linux 5 / 6 : unbreakable enterprise kernel (ELSA-2013-2589)

medium Nessus Plugin ID 71515

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 5 / 6 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2013-2589 advisory.

- The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgkill system call. (CVE-2013-2141)

- The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a crafted application that uses the UDP_CORK option in a setsockopt system call and sends both short and long packets, related to the ip_ufo_append_data function in net/ipv4/ip_output.c and the ip6_ufo_append_data function in net/ipv6/ip6_output.c. (CVE-2013-4470)

- The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value. (CVE-2013-6367)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2013-2589.html

Plugin Details

Severity: Medium

ID: 71515

File Name: oraclelinux_ELSA-2013-2589.nasl

Version: 1.15

Type: local

Agent: unix

Published: 12/18/2013

Updated: 9/8/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.9

Temporal Score: 6

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2013-4470

Vulnerability Information

CPE: cpe:/o:oracle:linux:5, cpe:/o:oracle:linux:6, p-cpe:/a:oracle:linux:kernel-uek, p-cpe:/a:oracle:linux:kernel-uek-debug, p-cpe:/a:oracle:linux:kernel-uek-debug-devel, p-cpe:/a:oracle:linux:kernel-uek-devel, p-cpe:/a:oracle:linux:kernel-uek-doc, p-cpe:/a:oracle:linux:kernel-uek-firmware, p-cpe:/a:oracle:linux:kernel-uek-headers, p-cpe:/a:oracle:linux:mlnx_en-2.6.32-400.33.4.el5uek, p-cpe:/a:oracle:linux:mlnx_en-2.6.32-400.33.4.el5uekdebug, p-cpe:/a:oracle:linux:mlnx_en-2.6.32-400.33.4.el6uek, p-cpe:/a:oracle:linux:mlnx_en-2.6.32-400.33.4.el6uekdebug, p-cpe:/a:oracle:linux:ofa-2.6.32-400.33.4.el5uek, p-cpe:/a:oracle:linux:ofa-2.6.32-400.33.4.el5uekdebug, p-cpe:/a:oracle:linux:ofa-2.6.32-400.33.4.el6uek, p-cpe:/a:oracle:linux:ofa-2.6.32-400.33.4.el6uekdebug

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Ease: No known exploits are available

Patch Publication Date: 12/16/2013

Vulnerability Publication Date: 6/3/2013

Reference Information

CVE: CVE-2013-2141, CVE-2013-4470, CVE-2013-6367

BID: 60254, 63359, 64270