security

Total 112
Today 0
profile_image
ino
03-05-20 12:49 0개 2,595회
Updated 2.4 kernel fixes security vulnerabilities and various bugs
Updated kernel packages that fix a remote denial of service vulnerability

in the TCP/IP stack, and a local privilege vulnerability, are now available.



The Linux kernel handles the basic functions of the operating system.



A flaw has been found in several hash table implementations in the kernel

networking code. A remote attacker could send packets with carefully

chosen, forged source addresses in such a way as to make every routing

cache entry get hashed into the same hash chain. The result would be that

the kernel would use a disproportionate amount of processor time to deal

with new packets, resulting in a remote denial of service attack. The

Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned

the name CAN-2003-0244 to this issue.



A flaw has been found in the "ioperm" system call, which fails to properly

restrict privileges. This flaw can allow an unprivileged local user to

gain read and write access to I/O ports on the system. The Common

Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name

CAN-2003-0246 to this issue.



All users should upgrade to these updated packages, which are not

vulnerable to these issues.


댓글목록

등록된 댓글이 없습니다.