Secunia Logo  


Secunia PSI WorldMap
 
Linux Kernel 2.4 Multiple Vulnerabilities
Secunia Advisory: SA9316
Release Date: 2003-07-22
Last Update: 2005-01-20
Popularity: 18,737 views

Critical:
Moderately critical
Impact: Privilege escalation
DoS
Where: From remote
Solution Status: Vendor Patch

OS:Astaro Security Linux 3.x
Conectiva Linux 7.0
Conectiva Linux 8
Conectiva Linux 9
Debian GNU/Linux 3.0
Gentoo Linux
Linux Kernel 2.4.x
Mandrake Linux 8.x
Mandrake Linux 9.x
OpenLinux Server 3.x
OpenLinux Workstation 3.x
Red Hat Enterprise Linux AS 2.1
Red Hat Enterprise Linux ES 2.1
Red Hat Enterprise Linux WS 2.1
Red Hat Linux 7.1
Red Hat Linux 7.2
Red Hat Linux 7.3
Red Hat Linux 8.0
Red Hat Linux Advanced Server 2.1 for Itanium
Red Hat Linux Advanced Workstation 2.1 for Itanium
Slackware Linux 8.x
Slackware Linux 9.0
SuSE Linux 7.x
SuSE Linux 8.x
SuSE Linux Connectivity Server
SuSE Linux Database Server
SuSE Linux Desktop 1.x
SuSE Linux Enterprise Server 7
SuSE Linux Enterprise Server 8
SuSE Linux Firewall on CD/Admin host
SuSE Linux Office Server

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 1 of 3)[ 1 ] [ 2 ] [ 3 ]

Description:
Multiple vulnerabilities has been identified in the Linux Kernel.

1) A local user can see the exact character count transmitted over a serial link. This can be exploited to see the length of password and to learn the inter-keystroke timings. This can be seen in "/proc/tty/driver/serial".

2) A race condition in the "execve()" system call, for more information see:
http://secunia.com/advisories/9154/

3) Normal users could bind to certain UDP ports due to an error in the RPC code.

4) The "execve()" system call stores file descriptors in the file table of the calling process. This allows local users to see restricted file descriptors.

5) Users are able to open entries in "/proc/self". This could cause setuid programs to fail changing ownership and permissions of already opened entries.

6) STP could allow malicious people to alter the bridge topology.

7) STP fails to check the length of data properly. This could lead to a Denial of Service.

8) It is possible to corrupt the forwarding table by sending forged packets (no further details are available).

9+10) Two security issues in the C-Media PCI sound driver result in userspace being accessed insecurely.

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

20th Nov, 2009
New advisories: 9
New vulnerabilities: 25
Updated advisories: 10

Highly // 381 views
SUSE update for java-1_6_0-sun
Moderately // 761 views
PHP Multiple Vulnerabilities

19th Nov, 2009
New advisories: 23
New vulnerabilities: 35
Updated advisories: 29


Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 48 views
2. Adobe Flash Player Multiple Vulnerabilities // 46 views
3. Dovecot Insecure Directory Permissions Security Issue // 36 views
4. Sun Java JDK / JRE Multiple Vulnerabilities // 36 views
5. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 31 views
6. Adobe Reader/Acrobat Multiple Vulnerabilities // 20 views
7. PHP Multiple Vulnerabilities // 18 views
8. Apache XML Security HMAC Truncation Spoofing // 12 views
9. Internet Explorer 7 Window Injection Vulnerability // 11 views
10. Opera Floating Point Number Processing Memory Corruption // 11 views