PT-2004-3751 · Opensuse+4 · Opensuse+4

Florian Zumbiehl

·

Publicado

1970-01-01

·

Atualizado

2017-10-11

·

CVE-2007-2525

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Debian GNU/Linux kernel-image versions 2.4.27-4-386 through 2.4.27-4-k7-smp Debian GNU/Linux kernel-headers versions 2.4.27-4-386 through 2.4.27-4-k7-smp Debian GNU/Linux kernel-pcmcia-modules versions 2.4.27-4-386 through 2.4.27-4-k7-smp Debian GNU/Linux pcmcia-modules versions 2.4.27-4-386 through 2.4.27-4-k7-smp SUSE Linux Enterprise kernel-default versions (affected versions not specified) openSUSE kernel-default versions (affected versions not specified)
Description The issue is related to multiple vulnerabilities in various Linux kernel packages, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The affected packages include kernel-image, kernel-headers, kernel-pcmcia-modules, and pcmcia-modules for Debian GNU/Linux, as well as kernel-default for SUSE Linux Enterprise and openSUSE. The exploitation of these vulnerabilities can result in a denial of service (memory consumption) by creating a socket using connect and releasing it before the PPPIOCGCHAN ioctl is initialized.
Recommendations For Debian GNU/Linux kernel-image versions 2.4.27-4-386 through 2.4.27-4-k7-smp, update to a newer version that contains a fix for this issue. For Debian GNU/Linux kernel-headers versions 2.4.27-4-386 through 2.4.27-4-k7-smp, update to a newer version that contains a fix for this issue. For Debian GNU/Linux kernel-pcmcia-modules versions 2.4.27-4-386 through 2.4.27-4-k7-smp, update to a newer version that contains a fix for this issue. For Debian GNU/Linux pcmcia-modules versions 2.4.27-4-386 through 2.4.27-4-k7-smp, update to a newer version that contains a fix for this issue. For SUSE Linux Enterprise kernel-default, update to a newer version that contains a fix for this issue. For openSUSE kernel-default, update to a newer version that contains a fix for this issue. As a temporary workaround, consider disabling the vulnerable kernel modules until a patch is available. Restrict access to the vulnerable kernel modules to minimize the risk of exploitation. Avoid using the affected kernel packages until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03581
BDU:2015-03582
BDU:2015-03583
BDU:2015-03584
BDU:2015-03585
BDU:2015-03586
BDU:2015-03587
BDU:2015-03588
BDU:2015-03589
BDU:2015-03590
BDU:2015-03591
BDU:2015-03592
BDU:2015-03593
BDU:2015-03594
BDU:2015-03595
BDU:2015-03596
BDU:2015-03597
BDU:2015-03598
BDU:2015-03599
BDU:2015-03600
BDU:2015-03601
BDU:2015-03602
BDU:2015-03603
BDU:2015-03604
BDU:2015-03605
BDU:2015-03606
BDU:2015-03607
BDU:2015-03608
BDU:2015-03609
BDU:2015-03610
BDU:2015-03611
BDU:2015-03612
BDU:2015-03613
BDU:2015-03614
BDU:2015-03615
BDU:2015-03616
BDU:2015-03617
BDU:2015-03618
BDU:2015-03619
BDU:2015-03620
BDU:2015-03621
BDU:2015-03622
BDU:2015-03623
BDU:2015-03624
BDU:2015-03625
BDU:2015-03626
BDU:2015-03627
BDU:2015-03628
BDU:2015-03629
BDU:2015-03630
BDU:2015-03631
BDU:2015-03632
BDU:2015-03633
BDU:2015-03634
BDU:2015-03635
BDU:2015-03636
BDU:2015-03637
BDU:2015-03638
BDU:2015-03639
BDU:2015-03640
BDU:2015-03641
BDU:2015-03642
BDU:2015-03643
BDU:2015-03644
BDU:2015-03645
BDU:2015-03646
BDU:2015-03647
BDU:2015-03648
BDU:2015-03649
BDU:2015-03650
BDU:2015-03651
BDU:2015-03652
BDU:2015-03653
BDU:2015-03654
BDU:2015-04220
BDU:2015-04221
BDU:2015-04222
BDU:2015-04223
BDU:2015-04224
BDU:2015-04225
BDU:2015-04726
BDU:2015-04727
BDU:2015-04728
BDU:2015-04729
BDU:2015-04730
BDU:2015-04731
BDU:2015-04732
BDU:2015-04733
BDU:2015-04734
BDU:2015-04735
BDU:2015-04736
BDU:2015-04737
BDU:2015-04738
BDU:2015-04739
BDU:2015-04740
BDU:2015-04741
BDU:2015-04742
BDU:2015-04743
BDU:2015-04744
BDU:2015-04745
BDU:2015-04746
BDU:2015-04747
BDU:2015-04748
BDU:2015-04749
BDU:2015-04750
BDU:2015-04751
BDU:2015-04752
BDU:2015-04753
BDU:2015-04754
BDU:2015-04755
BDU:2015-04756
BDU:2015-04757
BDU:2015-04758
BDU:2015-04759
BDU:2015-04760
BDU:2015-04761
BDU:2015-04762
BDU:2015-04763
BDU:2015-04764
BDU:2015-04765
BDU:2015-04766
BDU:2015-04767
BDU:2015-04768
BDU:2015-04769
BDU:2015-04770
BDU:2015-04771
BDU:2015-04772
BDU:2015-04773
BDU:2015-04774
BDU:2015-04775
BDU:2015-04776
BDU:2015-04777
BDU:2015-04778
BDU:2015-04779
BDU:2015-04780
BDU:2015-04781
BDU:2015-04782
BDU:2015-04783
BDU:2015-04784
BDU:2015-04785
BDU:2015-04786
BDU:2015-04787
BDU:2015-04898
BDU:2015-04899
BDU:2015-04900
BDU:2015-04901
BDU:2015-04902
BDU:2015-04903
BDU:2015-04904
BDU:2015-04905
BDU:2015-04906
BDU:2015-04907
BDU:2015-04908
BDU:2015-04909
BDU:2015-04910
BDU:2015-04911
BDU:2015-04912
BDU:2015-04913
BDU:2015-04914
BDU:2015-04915
BDU:2015-04916
BDU:2015-04917
BDU:2015-04967
BDU:2015-04968
CVE-2007-2525
DSA-1356-1
DSA-1503-1
DSA-1503-2
DSA-1504-1
RHSA-2007:0376
RHSA-2007:0488
RHSA-2007_0376
RHSA-2007_0488

Produtos afetados

Debian
Linux Kernel
Red Hat
Suse Linux Enterprise
Opensuse