Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Tue, 25 Mar 2014 10:07:10 -0500 Reply-To: Bonnie KingSender: Security Errata for Scientific Linux From: Bonnie King Subject: FASTBUGS for SL 6x i386, x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. In-Reply-To: <5328767C.1010900@fnal.gov> MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: autofs-5.0.5-89.el6_5.1.i686.rpm dmidecode-2.12-5.el6_5.i686.rpm environment-modules-3.2.10-1.el6_5.i686.rpm grep-2.6.3-4.el6_5.1.i686.rpm quota-3.17-21.el6_5.i686.rpm quota-devel-3.17-21.el6_5.i686.rpm spice-vdagent-0.14.0-3.el6_5.i686.rpm x86_64: autofs-5.0.5-89.el6_5.1.x86_64.rpm dmidecode-2.12-5.el6_5.x86_64.rpm environment-modules-3.2.10-1.el6_5.x86_64.rpm grep-2.6.3-4.el6_5.1.x86_64.rpm quota-3.17-21.el6_5.x86_64.rpm quota-devel-3.17-21.el6_5.i686.rpm quota-devel-3.17-21.el6_5.x86_64.rpm spice-vdagent-0.14.0-3.el6_5.x86_64.rpm Date: Tue, 25 Mar 2014 21:07:58 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific LinuxFrom: Pat Riehecky Subject: Security ERRATA Important: kernel on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2014:0328-1 Issue Date: 2014-03-25 CVE Numbers: CVE-2013-1860 CVE-2014-0055 CVE-2014-0069 CVE-2014-0101 -- * A flaw was found in the way the get_rx_bufs() function in the vhost_net implementation in the Linux kernel handled error conditions reported by the vhost_get_vq_desc() function. A privileged guest user could use this flaw to crash the host. (CVE-2014-0055, Important) * A flaw was found in the way the Linux kernel processed an authenticated COOKIE_ECHO chunk during the initialization of an SCTP connection. A remote attacker could use this flaw to crash the system by initiating a specially crafted SCTP handshake in order to trigger a NULL pointer dereference on the system. (CVE-2014-0101, Important) * A flaw was found in the way the Linux kernel's CIFS implementation handled uncached write operations with specially crafted iovec structures. An unprivileged local user with access to a CIFS share could use this flaw to crash the system, leak kernel memory, or, potentially, escalate their privileges on the system. Note: the default cache settings for CIFS mounts on Scientific Linux 6 prohibit a successful exploitation of this issue. (CVE-2014-0069, Moderate) * A heap-based buffer overflow flaw was found in the Linux kernel's cdc- wdm driver, used for USB CDC WCM device management. An attacker with physical access to a system could use this flaw to cause a denial of service or, potentially, escalate their privileges. (CVE-2013-1860, Low) The system must be rebooted for this update to take effect. -- SL6 x86_64 kernel-2.6.32-431.11.2.el6.x86_64.rpm kernel-debug-2.6.32-431.11.2.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm kernel-debug-devel-2.6.32-431.11.2.el6.x86_64.rpm kernel-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-431.11.2.el6.x86_64.rpm kernel-devel-2.6.32-431.11.2.el6.x86_64.rpm kernel-headers-2.6.32-431.11.2.el6.x86_64.rpm perf-2.6.32-431.11.2.el6.x86_64.rpm perf-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm python-perf-debuginfo-2.6.32-431.11.2.el6.x86_64.rpm python-perf-2.6.32-431.11.2.el6.x86_64.rpm i386 kernel-2.6.32-431.11.2.el6.i686.rpm kernel-debug-2.6.32-431.11.2.el6.i686.rpm kernel-debug-debuginfo-2.6.32-431.11.2.el6.i686.rpm kernel-debug-devel-2.6.32-431.11.2.el6.i686.rpm kernel-debuginfo-2.6.32-431.11.2.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-431.11.2.el6.i686.rpm kernel-devel-2.6.32-431.11.2.el6.i686.rpm kernel-headers-2.6.32-431.11.2.el6.i686.rpm perf-2.6.32-431.11.2.el6.i686.rpm perf-debuginfo-2.6.32-431.11.2.el6.i686.rpm python-perf-debuginfo-2.6.32-431.11.2.el6.i686.rpm python-perf-2.6.32-431.11.2.el6.i686.rpm noarch kernel-abi-whitelists-2.6.32-431.11.2.el6.noarch.rpm kernel-doc-2.6.32-431.11.2.el6.noarch.rpm kernel-firmware-2.6.32-431.11.2.el6.noarch.rpm - Scientific Linux Development Team