Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 3.0: DSA 336-2 Moderate Kernel Threats and Updates

debian
Calendar Grey July 1, 2003
Debian Logo
The latest advisory from Debian, DSA 336-2, addresses significant vulnerabilities in the kernel, detailing necessary actions for the update process.
This advisory is being released as a factual correction to DSA-336-1.

Summary

NOTE: This advisory is being released as a factual correction to
DSA-336-1. In an administrative error, DSA-336-1 listed several CVE
names which did not, in fact, apply to Linux 2.2.20, and omitted one
vulnerability which was fixed in the updated packages. The packages
are (and were) correct, and remain unchanged. The package changelog
contains the correct information. This advisory provides updated
information only.

A number of vulnerabilities have been discovered in the Linux kernel.

- - CVE-2002-0429: The iBCS routines in arch/i386/kernel/traps.c for
Linux kernels 2.4.18 and earlier on x86 systems allow local users to
kill arbitrary processes via a a binary compatibility interface
(lcall)

- - CAN-2003-0001: Multiple ethernet Network Interface Card (NIC) device
drivers do not pad frames with null bytes, which allows remote
attackers to obtain information from previous packets or kernel
memory by using malformed packets

- - CAN-2003-0127: The kernel module loader allows local users...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: kernel-source-2.2.20, kernel-image-2.2.20-i386

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here