Executive Summary
Summary | |
---|---|
Title | kernel security update |
Informations | |||
---|---|---|---|
Name | RHSA-2007:0085 | First vendor Publication | 2007-02-27 |
Vendor | RedHat | Last vendor Modification | 2007-02-27 |
Severity (Vendor) | Important | Revision | 01 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 4.7 | Attack Range | Local |
Cvss Impact Score | 6.9 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Problem Description: Updated kernel packages that fix two security issues and a bug in the Red Hat Enterprise Linux 4 kernel are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, noarch, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, noarch, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, noarch, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, noarch, x86_64 3. Problem description: The Linux kernel handles the basic functions of the operating system. These new kernel packages contain fixes for two security issues: * a flaw in the key serial number collision avoidance algorithm of the keyctl subsystem that allowed a local user to cause a denial of service (CVE-2007-0006, Important) * a flaw in the file watch implementation of the audit subsystems that allowed a local user to cause a denial of service (panic). To exploit this flaw a privileged user must have previously created a watch for a file (CVE-2007-0001, Moderate) In addition to the security issues described above, a fix for the SCTP subsystem to address a system crash which may be experienced in Telco environments has been included. Red Hat Enterprise Linux 4 users are advised to upgrade their kernels to the packages associated with their machine architecture and configurations as listed in this erratum. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 223129 - CVE-2007-0001 kernel panic watching /etc/passwd 223818 - kernel panic in sctp module 227495 - CVE-2007-0006 Key serial number collision problem |
Original Source
Url : https://rhn.redhat.com/errata/RHSA-2007-0085.html |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:9560 | |||
Oval ID: | oval:org.mitre.oval:def:9560 | ||
Title: | The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped. | ||
Description: | The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2007-0001 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-04-09 | Name : Mandriva Update for kernel MDKSA-2007:047 (kernel) File : nvt/gb_mandriva_MDKSA_2007_047.nasl |
2009-04-09 | Name : Mandriva Update for kernel MDKSA-2007:060 (kernel) File : nvt/gb_mandriva_MDKSA_2007_060.nasl |
2009-03-23 | Name : Ubuntu Update for linux-source-2.6.15/2.6.17 vulnerabilities USN-451-1 File : nvt/gb_ubuntu_USN_451_1.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-225 File : nvt/gb_fedora_2007_225_kernel_fc5.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-226 File : nvt/gb_fedora_2007_226_kernel_fc6.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-277 File : nvt/gb_fedora_2007_277_kernel_fc5.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-336 File : nvt/gb_fedora_2007_336_kernel_fc5.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-433 File : nvt/gb_fedora_2007_433_kernel_fc5.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-483 File : nvt/gb_fedora_2007_483_kernel_fc5.nasl |
2009-02-27 | Name : Fedora Update for kernel FEDORA-2007-599 File : nvt/gb_fedora_2007_599_kernel_fc5.nasl |
2009-01-28 | Name : SuSE Update for kernel SUSE-SA:2007:021 File : nvt/gb_suse_2007_021.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
33031 | Red Hat Enterprise Linux Kernel auditctl -w Local DoS |
33021 | Linux Kernel key_alloc_serial() Function Key Serial Number Collision Avoidanc... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0085.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-451-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_kernel-2705.nasl - Type : ACT_GATHER_INFO |
2007-05-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0099.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-060.nasl - Type : ACT_GATHER_INFO |
2007-02-28 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2007-0085.nasl - Type : ACT_GATHER_INFO |
2007-02-27 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0085.nasl - Type : ACT_GATHER_INFO |
2007-02-22 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-047.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:50:28 |
|