Fedora 9 : kernel-2.6.25.9-76.fc9 (2008-5893)

This script is Copyright (C) 2008-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

Update kernel from version 2.6.25.6 to 2.6.25.9:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.7
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.8
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9
Security updates: CVE-2008-2750: The pppol2tp_recvmsg function in
drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6
allows remote attackers to cause a denial of service (kernel heap
memory corruption and system crash) and possibly have unspecified
other impact via a crafted PPPOL2TP packet that results in a large
value for a certain length variable. CVE-2008-2358: The Datagram
Congestion Control Protocol (DCCP) subsystem in the Linux kernel
2.6.18, and probably other versions, does not properly check feature
lengths, which might allow remote attackers to execute arbitrary code,
related to an unspecified 'overflow.' Wireless driver updates: -
Upstream wireless fixes from 2008-06-27
(http://marc.info/?l=linux-wireless&m=121459423021061&w=2) - Upstream
wireless fixes from 2008-06-25 (http://marc.info/?l=linux-
wireless&m=121440912502527&w=2) - Upstream wireless updates from
2008-06-14 (http://marc.info/?l=linux-netdev&m=121346686508160&w=2) -
Upstream wireless fixes from 2008-06-09 (http://marc.info/?l=linux-
kernel&m=121304710726632&w=2) - Upstream wireless updates from
2008-06-09 (http://marc.info/?l=linux-netdev&m=121304710526613&w=2)
Bugs: 444694 - ALi Corporation M5253 P1394 OHCI 1.1 Controller driver
causing problems in kernels newer than 2.6.24.3-50 452595 - Problem
with SATA/IDE on Abit AN52 449080 - Rsync cannot copy to a vfat
partition on kernel 2.6.25 with -p or -a options 449909 - User Mode
Linux (UML) broken on Fedora 9 452111 - CVE-2008-2750 kernel: l2tp:
Fix potential memory corruption in pppol2tp-recvmsg() (Heap corruption
DoS) [F9] 449872 - [Patch] Bluetooth keyboard not reconnecting after
powersave

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://marc.info/?l=linux-
http://marc.info/?l=linux-netdev&m=121304710526613&w=2
http://marc.info/?l=linux-netdev&m=121346686508160&w=2
http://marc.info/?l=linux-wireless&m=121459423021061&w=2
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.7
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.8
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25.9
https://bugzilla.redhat.com/show_bug.cgi?id=444694
https://bugzilla.redhat.com/show_bug.cgi?id=449080
https://bugzilla.redhat.com/show_bug.cgi?id=449872
https://bugzilla.redhat.com/show_bug.cgi?id=449909
https://bugzilla.redhat.com/show_bug.cgi?id=452111
https://bugzilla.redhat.com/show_bug.cgi?id=452595
http://www.nessus.org/u?f5b9acba
http://www.nessus.org/u?7a593745

Solution :

Update the affected kernel package.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.8
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Fedora Local Security Checks

Nessus Plugin ID: 33404 (fedora_2008-5893.nasl)

Bugtraq ID: 29603
29747

CVE ID: CVE-2008-2358
CVE-2008-2750

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now