security

Total 112
Today 0
profile_image
ino
03-12-03 10:48 0개 3,068회
Updated 2.4 kernel fixes privilege escalation security vulnerability
Updated 2.4 kernel fixes privilege escalation security vulnerability



Advisory: RHSA-2003:392-05

Last updated on: 2003-12-01

Affected Products: Red Hat Linux 7.1

Red Hat Linux 7.2

Red Hat Linux 7.3

Red Hat Linux 8.0

Red Hat Linux 9

CVEs (cve.mitre.org): CAN-2003-0961



Security Advisory





Details:



Updated kernel packages are now available that fix a security vulnerability

leading to a possible privilege escalation.



The Linux kernel handles the basic functions of the operating system.



A flaw in bounds checking in the do_brk() function in the Linux kernel

versions 2.4.22 and previous can allow a local attacker to gain root

privileges. This issue is known to be exploitable; an exploit has been

seen in the wild that takes advantage of this vulnerability. The Common

Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name

CAN-2003-0961 to this issue.



All users are advised to upgrade to these errata packages, which contain

a backported security patch that corrects this vulnerability.



Important:



If you use Red Hat Linux 7.1, you must have installed quota-3.06-9.71 from

RHSA-2003:187, and if you use Red Hat Linux 7.2 or 7.3, you must have

installed quota-3.06-9.7 from RHSA-2003:187





Solution



Before applying this update, make sure all previously released errata

relevant to your system have been applied.



To use Red Hat Network to upgrade the kernel, launch the Red Hat Update

Agent with the following command:



up2date



This will start an interactive process that will result in the appropriate

RPMs being upgraded on your system. Note that you need to select the

kernel explicitly if you are using the default configuration of up2date.



To install kernel packages manually, use "rpm -ivh " and

modify system settings to boot the kernel you have installed. To

do this, edit /boot/grub/grub.conf and change the default entry to

"default=0" (or, if you have chosen to use LILO as your boot loader,

edit /etc/lilo.conf and run lilo)



Do not use "rpm -Uvh" as that will remove your running kernel binaries

from your system. You may use "rpm -e" to remove old kernels after

determining that the new kernel functions properly on your system.




댓글목록

등록된 댓글이 없습니다.