Linux Kernel NCPFS ncp_lookup() Unspecified Local Privilege Escalation Vulnerability Solution:
Turbolinux has released a security announcement (TLSA-2004-05-21) providing fixes that can be applied to x86 architecture based computers. Turbolinux users are advised to employ the turboupdate, turbopkg, and zabom utilities as a Superuser in order to obtain and apply appropriate fixes. Please see the referenced advisory for further details regarding obtaining and applying fixes.
Mandrake has released an advisory (MDKSA-2004:015) with fixes to address some of the issues described in this BID. Please see the referenced advisory for more information.
Red Hat has released advisories RHSA-2004:065-01 and RHSA-2004:069-06 to address this and other issues. Please see the referenced advisory for more information.
Red Hat has released an advisory FEDORA-2004-079 to address this and other issues. Please see the referenced advisory for more information.
SuSE has released advisory SA:2004:005 dealing with this issue. Please see the referenced advisory for more information.
Conectiva has released advisory CLA-2004:820 dealing with this issue. Please see the referenced advisory for more information.
Mandrake has released an updated advisory MDKSA-2004:015-1 to address this and other issues. Please see the referenced advisory for more information.
SGI has released an advisory 20040204-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information.
Fedora has released legacy advisory update FLSA:1284 fixing this issue in Red Hat linux 7.2, 7.3 and 8.0 for the i386, i586, i686 and athlon architectures. Please see the referenced advisory for details.
Debian has released advisories DSA 479-1 and DSA 482-1 as well as fixes dealing with this and other issues. Please see the attached advisory for more information and details on obtaining fixes.
Debian has released an update to the advisory DSA 479-1 providing fixes that deal with the IA-32 architecture. Apparently the original fixes are broken due to a build error. Please see the attached advisory for more information and details on obtaining updated fixes.
Debian has released advisory DSA 489-1 to provide updates for Linux 2.4.17 for the PowerPC/apus and S/390 architectures. Please see the attached advisory for details on applying and obtaining fixes.
Debian has released advisory DSA 491-1 to provide updates for Linux 2.4.19 on the MIPS architecture. Please see the attached advisory for details on applying and obtaining fixes.
Debian has released an advisory (DSA 495-1) to address various issues in the Linux kernel. This advisory contains fixes for the ARM architecture. Please see the referenced advisory for more information.
Red Hat has released advisory RHSA-2004:188-14 dealing with this and other issues for their enterprise linux distribution. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
SGI ProPack 2.4
Linux kernel 2.4.16
Linux kernel 2.4.17
Linux kernel 2.4.18
Linux kernel 2.4.19
Linux kernel 2.4.20
Linux kernel 2.4.21
Linux kernel 2.4.5
Linux kernel 2.4.9