Mandriva Linux Security Advisory : kernel (MDVSA-2009:148)

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.


Synopsis :

The remote Mandriva Linux host is missing one or more security
updates.

Description :

Some vulnerabilities were discovered and corrected in the Linux 2.6
kernel :

Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the
Linux kernel before 2.6.30 allows remote attackers to cause a denial
of service (kernel memory corruption and crash) via a long packet.
(CVE-2009-1389)

The inode double locking code in fs/ocfs2/file.c in the Linux kernel
2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before
2.6.29.4, and possibly other versions down to 2.6.19 allows local
users to cause a denial of service (prevention of file creation and
removal) via a series of splice system calls that trigger a deadlock
between the generic_file_splice_write, splice_from_pipe, and
ocfs2_file_splice_write functions. (CVE-2009-1961)

The nfs_permission function in fs/nfs/dir.c in the NFS client
implementation in the Linux kernel 2.6.29.3 and earlier, when
atomic_open is available, does not check execute (aka EXEC or
MAY_EXEC) permission bits, which allows local users to bypass
permissions and execute files, as demonstrated by files on an NFSv4
fileserver. (CVE-2009-1630)

Integer underflow in the e1000_clean_rx_irq function in
drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel
before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel
Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to
cause a denial of service (panic) via a crafted frame size.
(CVE-2009-1385)

Multiple buffer overflows in the cifs subsystem in the Linux kernel
before 2.6.29.4 allow remote CIFS servers to cause a denial of service
(memory corruption) and possibly have unspecified other impact via (1)
a malformed Unicode string, related to Unicode string area alignment
in fs/cifs/sess.c; or (2) long Unicode characters, related to
fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.
(CVE-2009-1633)

Additionally, the kernel package was updated to the Linux upstream
stable version 2.6.29.6.

To update your kernel, please follow the directions located at :

http://www.mandriva.com/en/security/kernelupdate

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.8
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Temporal Score : 6.8
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Mandriva Local Security Checks

Nessus Plugin ID: 48149 (mandriva_MDVSA-2009-148.nasl)

Bugtraq ID: 34612
34934
35143
35185
35281

CVE ID: CVE-2009-1385
CVE-2009-1389
CVE-2009-1630
CVE-2009-1633
CVE-2009-1961

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now