Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Linux Kernel do_brk Function Boundary Condition Vulnerability

Solution:
Sun has released a fix to address this issue in the Sun Cobalt RaQ 550. The fix is linked below.

Debian has released an advisory (DSA 423-1) that addresses the issue that is described in this BID for the IA-64 architecture. Further details regarding obtaining and applying fixes can be found in the referenced advisory.

RedHat has released security advisories RHSA-2003-389 and RHSA-2003:392-00 to address this issue. Additional information about associated fixes can be found in the appropriate advisory reference.

RedHat has also released advisory RHSA-2003:368-11 for affected versions of Enterprise Linux and Advanced Workstation Linux. Affected users are advised to run up2date to resolve this issue.

Debian has released a security advisory DSA-403-1 which contains a number of fixes to address this issue. Users are advised to see the referenced advisory for further details on how to obtain and apply fixes.

Mandrake has released a security advisory (MDKSA-2003:110) including fixes to address this issue. Information on how to obtain and apply fixes can be found in the referenced advisory.

Trustix has released a security advisory (TSLSA-2003-0046) including fixes to address this issue. Fixes are available below.

This issue has also been addressed in the Linux 2.4.23 and 2.6.0-test6 releases. Users are advised to upgrade as soon as possible.

Astaro has released fixes Astaro Security Linux 4.017 (new V4 ISO) and Up2date 4.017 to address this issue. Please see the referenced web sites for more information.

Slackware Linux has released an advisory SSA:2003-336-01 including fixes to address this issue.

SGI has released an advisory (20031201-01-A) to address this issue. SGI have reported that SGI ProPack version 2.3 is not vulnerable to this issue, customers who have not received ProPack version 2.3 CD's are advised to contact the SGI Support Provider. Please see the referenced advisory for further details.

TurboLinux has released a security announcment including fixes to address this issue.

Yellow Dog Linux has released advisory YDU-20031203-1 to address this issue.

Advisory SuSE-SA:2003:049 has been released by SuSE to resolve this issue.

Gentoo has released advisory 200312-02 to address this issue. Affected users are advised to perform the following actions:

emerge sync
emerge -pv [your preferred kernel sources]
emerge [your preferred kernel sources]
[update the /usr/src/linux symlink]
[compile and install your new kernel]
[emerge any necessary kernel module ebuilds]
[reboot]

Conectiva has released a security advisory CLA-2003:796 including fixes to address this issue.

SmoothWall has released fixes to address this issue in SmoothWall Express 2.0. Users are advised to obtain the fixes through the SmoothWall interface. Please see the referenced web page for more information. Users may download the fixes1 patch by carrying out the following steps:

Go to Maintenance -> Updates on your SmoothWall web interface, and upload the file called fixes1.

SGI has released a security advisory 20040102-01-U including fixes to address this issue. Please see the attached advisory for more information.

Debian has released advisory DSA-433-1 this issue for the mips and mipsel architectures.

VMWare has released a fix to address this issue in VMWare ESX Server 2.0.1 build 6403. Please see the referenced web page for more information.

Debian has released two advisories DSA-439-1 and DSA-440-1 to address this and other issues. Please see the referenced advisories for more information.

Debian has released DSA 442-1 to provide fixes for s390 platforms. Please see the attached advisory for further information.

Debian has released DSA 450-1 to provide MIPS kernel fixes. Please see the attached advisory for further details.

Debian has released DSA 470-1 to address this and other issues in the HP Precision architecture. Please see the referenced advisory for more information.

VMWare advisory and fixes available for their ESX server package. Please see th reference section for more information.

Debian has released advisory DSA 475-1 with fixes dealing with this and other issues for the HP Precision architecture.

Fixes:


Sun Cobalt RaQ 550

Trustix Secure Linux 2.0

VMWare ESX Server 2.0

VMWare ESX Server 2.0.1 build 6403

VMWare ESX Server 2.0.1

Linux kernel 2.4

Linux kernel 2.4.1

Linux kernel 2.4.11

Linux kernel 2.4.12

Linux kernel 2.4.13

Linux kernel 2.4.14

Linux kernel 2.4.15

Linux kernel 2.4.17

Linux kernel 2.4.18

Linux kernel 2.4.19

Linux kernel 2.4.21

Linux kernel 2.4.22

Linux kernel 2.4.3

Linux kernel 2.4.4

Linux kernel 2.4.5

Linux kernel 2.4.6

Linux kernel 2.4.7

Linux kernel 2.4.8

Linux kernel 2.4.9

Linux kernel 2.5 .0

Linux kernel 2.5.10

Linux kernel 2.5.11

Linux kernel 2.5.12

Linux kernel 2.5.15

Linux kernel 2.5.16

Linux kernel 2.5.17

Linux kernel 2.5.18

Linux kernel 2.5.19

Linux kernel 2.5.2

Linux kernel 2.5.21

Linux kernel 2.5.22

Linux kernel 2.5.23

Linux kernel 2.5.24

Linux kernel 2.5.25

Linux kernel 2.5.26

Linux kernel 2.5.27

Linux kernel 2.5.28

Linux kernel 2.5.29

Linux kernel 2.5.3

Linux kernel 2.5.30

Linux kernel 2.5.31

Linux kernel 2.5.32

Linux kernel 2.5.33

Linux kernel 2.5.35

Linux kernel 2.5.36

Linux kernel 2.5.37

Linux kernel 2.5.4

Linux kernel 2.5.40

Linux kernel 2.5.42

Linux kernel 2.5.43

Linux kernel 2.5.45

Linux kernel 2.5.48

Linux kernel 2.5.49

Linux kernel 2.5.5

Linux kernel 2.5.51

Linux kernel 2.5.52

Linux kernel 2.5.53

Linux kernel 2.5.54

Linux kernel 2.5.55

Linux kernel 2.5.56

Linux kernel 2.5.57

Linux kernel 2.5.58

Linux kernel 2.5.59

Linux kernel 2.5.6

Linux kernel 2.5.60

Linux kernel 2.5.62

Linux kernel 2.5.63

Linux kernel 2.5.64

Linux kernel 2.5.65

Linux kernel 2.5.67

Linux kernel 2.5.7

Linux kernel 2.5.8

Linux kernel 2.6 -test4

Linux kernel 2.6 -test2

Linux kernel 2.6 -test3

Linux kernel 2.6 -test1







 

Privacy Statement
Copyright 2009, SecurityFocus