Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o
Subject: [gentoo-announce] GLSA: gentoo-sources (200308-01)
Date: Thu, 14 Aug 2003 12:52:48
Message-Id: 20030814121629.DE3F99FBE4@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200308-01
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : gentoo-sources
9           SUMMARY : multiple vulnerabilities
10              DATE : 2003-08-14 12:16 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <gentoo-sources-2.4.20-r6
13     FIXED VERSION : >=gentoo-sources-2.4.20-r6
14               CVE : CAN-2003-0244 CAN-2003-0246 CAN-2003-0462
15
16 - - - ---------------------------------------------------------------------
17
18 - - quotes from CVE:
19
20 "The route cache implementation in Linux 2.4, and the Netfilter IP
21 conntrack module, allows remote attackers to cause a denial of service
22 (CPU consumption) via packets with forged source addresses that cause a
23 large number of hash table collisions."
24
25 "The ioperm system call in Linux kernel 2.4.20 and earlier does not
26 properly restrict privileges, which allows local users to gain read or
27 write access to certain I/O ports."
28
29 "A race condition in the way env_start and env_end pointers are
30 initialized in the execve system call and used in fs/proc/base.c on
31 Linux 2.4 allows local users to cause a denial of service (crash)."
32
33 SOLUTION
34
35 It is recommended that all Gentoo Linux users who are running
36 sys-kernel/gentoo-sources upgrade to gentoo-sources-2.4.20-r6 as follows
37
38 emerge sync
39 emerge gentoo-sources
40 emerge clean
41
42 After that, compile, install and reboot your computer to complete
43 the upgrade.
44
45 - - - ---------------------------------------------------------------------
46 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
47 - - - ---------------------------------------------------------------------
48 -----BEGIN PGP SIGNATURE-----
49 Version: GnuPG v1.2.2 (GNU/Linux)
50
51 iD8DBQE/O32dfT7nyhUpoZMRAvRRAJ9gKhIHNvEKkhnIGh50DV06W93E/gCffg3L
52 foJIctGEKqdWsL9tFbFxArI=
53 =qIHR
54 -----END PGP SIGNATURE-----