|
|
Subscribe / Log in / New account

Pardus alert 2010-94 (kernel kernel-pae)

From:  Eren Turkay <eren@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2010-94] Kernel: Multiple Vulnerabilities
Date:  Thu, 8 Jul 2010 13:54:21 +0300 (EEST)
Message-ID:  <20100708105421.79F03A7AB50@lider.pardus.org.tr>

------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-94 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-07-08 Severity: 4 Type: Remote ------------------------------------------------------------------------ Summary ======= Multiple vulnerabilities have been fixed in kernel. Description =========== CVE-2010-1641: The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request. CVE-2010-1636: The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to read sensitive information from a write-only file descriptor. CVE-2010-2071: The btrfs_xattr_set_acl function in fs/btrfs/acl.c in btrfs in the Linux kernel 2.6.34 and earlier does not check file ownership before setting an ACL, which allows local users to bypass file permissions by setting arbitrary ACLs, as demonstrated using setfacl. CVE-2010-2066: If the donor file is an append-only file, we should not allow the operation to proceed, lest we end up overwriting the contents of an append-only file. Affected packages: Pardus 2009: kernel, all before 2.6.31.13-131-46 kernel-pae, all before 2.6.31.13-131-27 Resolution ========== There are update(s) for kernel, kernel-pae. You can update them via Package Manager or with a single command from console: pisi up kernel kernel-pae References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=13450 * http://bugs.pardus.org.tr/show_bug.cgi?id=13292 * http://bugs.pardus.org.tr/show_bug.cgi?id=13490 * http://bugs.pardus.org.tr/show_bug.cgi?id=13289 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds