Linux kernel gain privileges
| linux-gain-privileges (16625) |
Description:
Linux kernel could allow a local attacker to gain elevated privileges on the system or gain access to kernel memory.
Consequences:
Gain Privileges
Remedy:
For SuSE Linux:
Upgrade to the latest kernel package, as listed below. Refer to SuSE Security Announcement SUSE-SA:2004:020 for more information. See References.
SuSE Linux 9.1: 2.6.5-7.95 or later
SuSE Linux 9.0: 2.4.21-231 or later
SuSE Linux 8.2: 2.4.20-115 or later
SuSE Linux 8.1: 2.4.21-231 or later
SuSE Linux 8.0: 2.4.18-303 or later
For Mandrake Linux:
Upgrade to the latest kernel package, as listed below. Refer to MandrakeSoft Security Advisory MDKSA-2004:066 : kernel for more information.See References.
Mandrake Linux 9.1: 2.4.21.0.32mdk-1-1mdk or later
Mandrake Linux 9.2: 2.4.22.36mdk-1-1mdk or later
Mandrake Linux Multi Network Firewall 8.2: 2.4.19.43mdk-1-1mdk or later
Mandrake Linux Corporate Server 2.1: 2.4.19.43mdk-1-1mdk or later
Mandrake Linux 10.0: 2.4.25.7mdk-1-1mdk or later
For Gentoo Linux:
Upgrade to the latest version of kernel, as listed in GLSA 200407-16. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
References:
- BID-10779: Linux Kernel Multiple Unspecified Local Privilege Escalation Vulnerabilities
- CVE-2004-0496: Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
- GLSA-200407-16: Linux Kernel: Multiple DoS and permission vulnerabilities
- SUSE-SA:2004:020: kernel: local privilege escalation
Platforms Affected:
- Gentoo Linux
- Linux Kernel 2.6.0
- MandrakeSoft Mandrake Linux 10.0
- MandrakeSoft Mandrake Linux 9.1
- MandrakeSoft Mandrake Linux 9.2
- MandrakeSoft Mandrake Linux Corporate Server 2.1
- MandrakeSoft Mandrake Multi Network Firewall 8.2
- Novell SuSE Linux Enterprise Server 7.0
- Sun Solaris 8
- Sun Solaris 8.1
- Sun Solaris 8.2
- Sun Solaris 9
- Sun Solaris 9.1
- SuSE Linux Enterprise Server 8
- SuSE SuSE eMail Server 3.1
- SuSE SuSE eMail Server III
- SUSE SuSE Linux 8.0
- SUSE SuSE Linux 8.1
- SUSE SuSE Linux 8.2
- SUSE SuSE Linux 9.0
- SUSE SuSE Linux 9.1
- SuSE SuSE Linux Connectivity Server
- SuSE SuSE Linux Database Server
- SuSE SuSE Linux Firewall
- SuSE SuSE Linux Office Server
Reported:
Jul 02, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
