Scientific Linux Security Update : kernel on SL5.x i386/x86_64

medium Nessus Plugin ID 60209

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

a flaw in the mount handling routine for 64-bit systems that allowed a local user to cause denial of service (CVE-2006-7203, Important).

a flaw in the PPP over Ethernet implementation that allowed a remote user to cause a denial of service (CVE-2007-2525, Important).

a flaw in the Bluetooth subsystem that allowed a local user to trigger an information leak (CVE-2007-1353, Low).

a bug in the random number generator that prevented the manual seeding of the entropy pool (CVE-2007-2453, Low).

In addition to the security issues described above, fixes for the following have been included :

- a race condition between ext3_link/unlink that could create an orphan inode list corruption.

- a bug in the e1000 driver that could lead to a watchdog timeout panic.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?0d49467d

Plugin Details

Severity: Medium

ID: 60209

File Name: sl_20070614_kernel_on_SL5_x.nasl

Version: 1.5

Type: local

Agent: unix

Published: 8/1/2012

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.7

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 6/14/2007

Reference Information

CVE: CVE-2006-7203, CVE-2007-1353, CVE-2007-2453, CVE-2007-2525