Fedora 7 : kernel-2.6.22.4-65.fc7 (2007-1785)

low Nessus Plugin ID 27734

Synopsis

The remote Fedora host is missing a security update.

Description

Update to kernel 2.6.22.2, 2.6.22.3 and 2.6.22.4:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.2 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.3 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.4

- Fix failure to find serial ports on some machines.

- Detect broken timers on some AMD dual-core machines:
fixes hangs and failure to boot.

- Don't crash when a userspace driver requests too much memory.

- Update the CFS scheduler to more closely match upstream.

- Wireless driver update.

- Enable ACPI_DEBUG in -debug builds.

- Fix e820 memory hole sizing on x86_64.

- Add four bugfixes for sky2 ethernet.

- Fix some SCSI async scanning bugs.

- Fix polling in r8169 driver.

- Fix wrong sensor values with some chips.

CVE-2007-3848: Linux kernel 2.4.35 and other versions allows local users to send arbitrary signals to a child process that is running at higher privileges by causing a setuid-root parent process to die, which delivers an attacker-controlled parent process death signal (PR_SET_PDEATHSIG).

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?e81b5005

http://www.nessus.org/u?898c6269

http://www.nessus.org/u?3bf7926d

http://www.nessus.org/u?87df7cb8

Plugin Details

Severity: Low

ID: 27734

File Name: fedora_2007-1785.nasl

Version: 1.14

Type: local

Agent: unix

Published: 11/6/2007

Updated: 1/11/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Low

Base Score: 1.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:kernel-debuginfo, p-cpe:/a:fedoraproject:fedora:kernel-pae-devel, cpe:/o:fedoraproject:fedora:7, p-cpe:/a:fedoraproject:fedora:kernel-debug, p-cpe:/a:fedoraproject:fedora:kernel-debug-devel, p-cpe:/a:fedoraproject:fedora:kernel-devel, p-cpe:/a:fedoraproject:fedora:kernel-doc, p-cpe:/a:fedoraproject:fedora:kernel, p-cpe:/a:fedoraproject:fedora:kernel-debug-debuginfo, p-cpe:/a:fedoraproject:fedora:kernel-pae-debug, p-cpe:/a:fedoraproject:fedora:kernel-pae-debug-debuginfo, p-cpe:/a:fedoraproject:fedora:kernel-headers, p-cpe:/a:fedoraproject:fedora:kernel-debuginfo-common, p-cpe:/a:fedoraproject:fedora:kernel-pae, p-cpe:/a:fedoraproject:fedora:kernel-pae-debuginfo, p-cpe:/a:fedoraproject:fedora:kernel-pae-debug-devel

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 8/23/2007

Reference Information

CVE: CVE-2007-3848

FEDORA: 2007-1785