O-059: Debian Linux-Kernel-2.4.17-ia64 Vulnerabilities Privacy and Legal Notice

CIAC INFORMATION BULLETIN

O-059: Debian Linux-Kernel-2.4.17-ia64 Vulnerabilities

[DSA-423-1]

January 15, 2004 18:00 GMT
[REVISED 2 Mar 2004]

PROBLEM: The IA-64 maintainers fixed several security related bugs in the Linux kernel 2.4.17 used for the IA-64 architecture.
PLATFORM: Linux kernel 2.4.17-ia64
DAMAGE: The most serious of these vulnerabilities may allow an unprivileged local user to gain root access.
SOLUTION: Install the security update.

VULNERABILITY
ASSESSMENT:
The risk is MEDIUM. An unprivileged local use may gain root access.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/o-059.shtml
  ORIGINAL BULLETIN: Debian Security Advisory DSA-423-1
http://www.debian.org/security/2004/dsa-423
Debian Security Advisory DSA-442-1
http://www.debian.org/security/2004/dsa-442
  CVE/CAN: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=
CVE-2003-0001, CVE-2003-0018, CVE-2003-0127, CVE-2003-0461, CVE-2003-0462, CVE-2003-0476, CVE-2003-0501, CVE-2003-0550, CVE-2003-0551, CVE-2003-0552, CVE-2003-0961, CVE-2003-0985

Revision History:
3/2/04 - Added link to Debian DSA 442-1 for patches fixing vulnerabilities on 
         network interface card (NIC) device drivers and for the do_brk 
         function.

		 
[***** Start DSA-423-1 *****]

Debian Security Advisory

DSA-423-1 linux-kernel-2.4.17-ia64 -- several vulnerabilities

Date Reported: 
15 Jan 2004 
Affected Packages: 
kernel-image-2.4.17-ia64 
Vulnerable: 
Yes 
Security database references: 
In Mitre's CVE dictionary: 
CAN-2003-0001, CVE-2003-0018, CVE-2003-0127, CVE-2003-0461, CVE-2003-0462, CVE-2003-0476, CVE-2003-0501, 
CVE-2003-0550, CVE-2003-0551, CVE-2003-0552, CVE-2003-0961, CVE-2003-0985	

More information: 

The IA-64 maintainers fixed several security related bugs in the Linux kernel 2.4.17 used for the IA-64 
architecture, mostly by backporting fixes from 2.4.18. The corrections are listed below with the 
identification from the Common Vulnerabilities and Exposures (CVE) project:


For the stable distribution (woody) this problem has been fixed in version kernel-image-2.4.17-ia64 for the ia64 
architecture. Other architectures are already or will be fixed separately.

For the unstable distribution (sid) this problem will be fixed soon with newly uploaded packages.

Fixed in: 
Debian GNU/Linux 3.0 (woody)
Source: 
http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-image-2.4.17-ia64_011226.15.dsc

http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-image-2.4.17-ia64_011226.15.tar.gz

Architecture-independent component: 
http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-source-2.4.17-ia64_011226.15_all.deb

Intel IA-64: 
http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-headers-2.4.17-ia64_011226.15_ia64.deb

http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-image-2.4.17-itanium_011226.15_ia64.deb

http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-image-2.4.17-itanium-smp_011226.15_ia64.deb

http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-image-2.4.17-mckinley_011226.15_ia64.deb

http://security.debian.org/pool/updates/main/k/kernel-image-2.4.17-ia64/kernel-image-2.4.17-mckinley-smp_011226.15_ia64.deb

MD5 checksums of the listed files are available in the original advisory.


--------------------------------------------------------------------------------
This page is also available in the following languages: 
dansk  
How to set the default document language 
--------------------------------------------------------------------------------

See the Debian contact page for information on contacting us.

Last Modified: Thu, Jan 15 14:36:49 UTC 2004 
Copyright © 2004 SPI; See license terms
Debian is a registered trademark of Software in the Public Interest, Inc. 


[***** End DSA-423-1 *****]


CIAC wishes to acknowledge the contributions of Debian for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/