int(996)

Vulnerability Bulletins


Denegación de servicio remota en Linux Kernel

Vulnerability classification

Property Value
Confidence level Oficial
Impact Denegación de Servicio
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer GNU/Linux
Affected software Linux kernel version 2.6
Linux kernel version 2.4

Description

Se han detectado desbordamientos de entero en las funciones kNFSd y XDR en kernel 2.6.Estas vulnerabilidades pueden ser explotadas remotamente enviando un paquete con una IP origen confiable y haciendo peticiones con un tamañan mayor a 2^31.

Solution



Actualización de software

Suse Linux

x86 Platform - SUSE Linux 9.1
RPM
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2.6.5-7.108.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6.5-7.108.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5-7.108.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-source-2.6.5-7.108.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-syms-2.6.5-7.108.i586.rpm
source rpm(s)
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/src/kernel-default-2.6.5-7.108.nosrc.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/src/kernel-bigsmp-2.6.5-7.108.nosrc.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/src/kernel-smp-2.6.5-7.108.nosrc.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/src/kernel-source-2.6.5-7.108.src.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/src/kernel-syms-2.6.5-7.108.src.rpm

x86-64 Platform - SUSE Linux 9.1
RPM
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-default-2.6.5-7.108.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-smp-2.6.5-7.108.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-source-2.6.5-7.108.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-syms-2.6.5-7.108.x86_64.rpm
source rpm(s)
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/src/kernel-default-2.6.5-7.108.nosrc.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/src/kernel-smp-2.6.5-7.108.nosrc.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/src/kernel-source-2.6.5-7.108.src.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/src/kernel-syms-2.6.5-7.108.src.rpm

Standar resources

Property Value
CVE
BID

Other resources

SUSE Security Announcement: kernel (SUSE-SA:2004:028)
http://www.suse.de/de/security/2004_28_kernel.html

Version history

Version Comments Date
1.0 Aviso emitido 2004-09-03
Ministerio de Defensa
CNI
CCN
CCN-CERT