Linux Kernel SCSI IOCTL Integer Overflow Vulnerability

Solution:
SuSE has released a security announcement (SUSE-SA:2005:003) and fixes to address the vulnerability described in this BID and also other vulnerabilities. Customers are advised to peruse the referenced announcement for further details in regard to obtaining and applying appropriate fixes.

RedHat has released two advisories called FEDORA-2005-013 and FEDORA-2005-014 to address this, and other issues for Fedora Core 2 and 3. Please see the referenced advisories for further information.

Red Hat has released advisory RHSA-2005:092-14 to address various issues in the kernel. Please see the advisory in Web references for more information.

SuSE has released security advisory SUSE-SA:2005:010 dealing with an issue that has arisen due to a broken patch previously released. Apparently due to various new checks being performed computers running an NVidia graphics card may experience a denial of service condition when X Windows is started. This issue affects SuSE Linux 9.1, SuSE Linux Enterprise Server 9, and Novell Linux Desktop 9.

Mandriva has released advisory MDKSA-2005:218 to address various issues affecting the Linux Kernel. Please see the referenced advisory for more information.

Mandriva has released advisory MDKSA-2005:219 to address various issues affecting the Linux Kernel in Mandrake Linux 10.1. Please see the referenced advisory for more information.


Linux kernel 2.6.3

Linux kernel 2.6.4

Linux kernel 2.6.5

Linux kernel 2.6.8 rc1

Linux kernel 2.6.8

Linux kernel 2.6.9


 

Privacy Statement
Copyright 2010, SecurityFocus