Executive Summary
Summary | |
---|---|
Title | linux security update |
Informations | |||
---|---|---|---|
Name | DSA-3372 | First vendor Publication | 2015-10-13 |
Vendor | Debian | Last vendor Modification | 2015-10-13 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 6.9 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, unauthorised information disclosure or unauthorised information modification. CVE-2015-2925 Jann Horn discovered that when a subdirectory of a filesystem was bind-mounted into a chroot or mount namespace, a user that should be confined to that chroot or namespace could access the whole of that filesystem if they had write permission on an ancestor of the subdirectory. This is not a common configuration for wheezy, and the issue has previously been fixed for jessie. CVE-2015-5257 Moein Ghasemzadeh of Istuary Innovation Labs reported that a USB device could cause a denial of service (crash) by imitating a Whiteheat USB serial device but presenting a smaller number of endpoints. CVE-2015-5283 Marcelo Ricardo Leitner discovered that creating multiple SCTP sockets at the same time could cause a denial of service (crash) if the sctp module had not previously been loaded. This issue only affects jessie. CVE-2015-7613 Dmitry Vyukov discovered that System V IPC objects (message queues and shared memory segments) were made accessible before their ownership and other attributes were fully initialised. If a local user can race against another user or service creating a new IPC object, this may result in unauthorised information disclosure, unauthorised information modification, denial of service and/or privilege escalation. A similar issue existed with System V semaphore arrays, but was less severe because they were always cleared before being fully initialised. For the oldstable distribution (wheezy), these problems have been fixed in version 3.2.68-1+deb7u5. For the stable distribution (jessie), these problems have been fixed in version 3.16.7-ckt11-1+deb8u5. For the unstable distribution (sid), these problems have been fixed in version 4.2.3-1 or earlier versions. We recommend that you upgrade your linux packages. |
Original Source
Url : http://www.debian.org/security/2015/dsa-3372 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-362 | Race Condition |
50 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2017-05-17 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2017-0106.nasl - Type : ACT_GATHER_INFO |
2017-05-17 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2017-0105.nasl - Type : ACT_GATHER_INFO |
2017-05-17 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2017-3567.nasl - Type : ACT_GATHER_INFO |
2017-05-17 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2017-3566.nasl - Type : ACT_GATHER_INFO |
2017-05-01 | Name : The remote EulerOS host is missing multiple security updates. File : EulerOS_SA-2016-1018.nasl - Type : ACT_GATHER_INFO |
2017-04-03 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2017-0057.nasl - Type : ACT_GATHER_INFO |
2017-02-28 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL37510383.nasl - Type : ACT_GATHER_INFO |
2016-03-18 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2016-0037.nasl - Type : ACT_GATHER_INFO |
2016-03-04 | Name : The remote Fedora host is missing a security update. File : fedora_2015-dcc260f2f2.nasl - Type : ACT_GATHER_INFO |
2016-03-04 | Name : The remote Fedora host is missing a security update. File : fedora_2015-d7e074ba30.nasl - Type : ACT_GATHER_INFO |
2016-03-04 | Name : The remote Fedora host is missing a security update. File : fedora_2015-43145298f4.nasl - Type : ACT_GATHER_INFO |
2016-03-04 | Name : The remote Fedora host is missing a security update. File : fedora_2015-3c8c8ba072.nasl - Type : ACT_GATHER_INFO |
2016-02-04 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-2587.nasl - Type : ACT_GATHER_INFO |
2016-02-04 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-2411.nasl - Type : ACT_GATHER_INFO |
2016-02-03 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2016-124.nasl - Type : ACT_GATHER_INFO |
2016-01-27 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2016-0068.nasl - Type : ACT_GATHER_INFO |
2016-01-14 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL31026324.nasl - Type : ACT_GATHER_INFO |
2016-01-11 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-3503.nasl - Type : ACT_GATHER_INFO |
2016-01-11 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2016-3502.nasl - Type : ACT_GATHER_INFO |
2015-12-22 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20151119_kernel_on_SL7_x.nasl - Type : ACT_GATHER_INFO |
2015-12-18 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-2292-1.nasl - Type : ACT_GATHER_INFO |
2015-12-17 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL90230486.nasl - Type : ACT_GATHER_INFO |
2015-12-16 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20151215_kernel_on_SL6_x.nasl - Type : ACT_GATHER_INFO |
2015-12-16 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-2636.nasl - Type : ACT_GATHER_INFO |
2015-12-16 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-2636.nasl - Type : ACT_GATHER_INFO |
2015-12-16 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-2636.nasl - Type : ACT_GATHER_INFO |
2015-12-07 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2829-2.nasl - Type : ACT_GATHER_INFO |
2015-12-07 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2829-1.nasl - Type : ACT_GATHER_INFO |
2015-12-07 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-2194-1.nasl - Type : ACT_GATHER_INFO |
2015-12-04 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2826-1.nasl - Type : ACT_GATHER_INFO |
2015-12-02 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2823-1.nasl - Type : ACT_GATHER_INFO |
2015-12-02 | Name : The remote OracleVM host is missing one or more security updates. File : oraclevm_OVMSA-2015-0150.nasl - Type : ACT_GATHER_INFO |
2015-12-02 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2015-2152.nasl - Type : ACT_GATHER_INFO |
2015-11-30 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-3101.nasl - Type : ACT_GATHER_INFO |
2015-11-30 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2015-2152.nasl - Type : ACT_GATHER_INFO |
2015-11-20 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2015-2152.nasl - Type : ACT_GATHER_INFO |
2015-11-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2795-1.nasl - Type : ACT_GATHER_INFO |
2015-11-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2792-1.nasl - Type : ACT_GATHER_INFO |
2015-11-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2794-1.nasl - Type : ACT_GATHER_INFO |
2015-11-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2797-1.nasl - Type : ACT_GATHER_INFO |
2015-11-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2798-1.nasl - Type : ACT_GATHER_INFO |
2015-11-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2799-1.nasl - Type : ACT_GATHER_INFO |
2015-10-30 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2015-686.nasl - Type : ACT_GATHER_INFO |
2015-10-29 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2015-603.nasl - Type : ACT_GATHER_INFO |
2015-10-14 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2015-1727-1.nasl - Type : ACT_GATHER_INFO |
2015-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3372.nasl - Type : ACT_GATHER_INFO |
2015-10-13 | Name : The remote Debian host is missing a security update. File : debian_DLA-325.nasl - Type : ACT_GATHER_INFO |
2015-10-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2765-1.nasl - Type : ACT_GATHER_INFO |
2015-10-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2764-1.nasl - Type : ACT_GATHER_INFO |
2015-10-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2763-1.nasl - Type : ACT_GATHER_INFO |
2015-10-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2762-1.nasl - Type : ACT_GATHER_INFO |
2015-10-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-2761-1.nasl - Type : ACT_GATHER_INFO |
2015-09-22 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-3364.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2015-11-16 17:26:23 |
|
2015-10-20 00:27:51 |
|
2015-10-19 17:29:12 |
|
2015-10-15 13:23:59 |
|
2015-10-13 13:22:20 |
|