Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability
BID:10852
Info
Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability
| Bugtraq ID: | 10852 |
| Class: | Design Error |
| CVE: |
CVE-2004-0415 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 04 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of this issue is credited to Paul Starzetz <[email protected]>. |
| Vulnerable: |
VMWare ESX Server 2.1.2 VMWare ESX Server 2.1.1 VMWare ESX Server 2.0.1 build 6403 VMWare ESX Server 2.0.1 VMWare ESX Server 2.0 build 5257 VMWare ESX Server 2.0 Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Enterprise Linux 2.0 SGI ProPack 3.0 Redhat Fedora Core1 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Linux kernel 2.4.26 Linux kernel 2.4.25 Linux kernel 2.4.24 -ow1 Linux kernel 2.4.24 Linux kernel 2.4.23 -pre9 Linux kernel 2.4.23 -ow2 Linux kernel 2.4.23 Linux kernel 2.4.22 Linux kernel 2.4.21 pre7 Linux kernel 2.4.21 pre4 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.4.20 Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.19 Linux kernel 2.4.18 pre-8 Linux kernel 2.4.18 pre-7 Linux kernel 2.4.18 pre-6 Linux kernel 2.4.18 pre-5 Linux kernel 2.4.18 pre-4 Linux kernel 2.4.18 pre-3 Linux kernel 2.4.18 pre-2 Linux kernel 2.4.18 pre-1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 .0-test9 Linux kernel 2.4 .0-test8 Linux kernel 2.4 .0-test7 Linux kernel 2.4 .0-test6 Linux kernel 2.4 .0-test5 Linux kernel 2.4 .0-test4 Linux kernel 2.4 .0-test3 Linux kernel 2.4 .0-test2 Linux kernel 2.4 .0-test12 Linux kernel 2.4 .0-test11 Linux kernel 2.4 .0-test10 Linux kernel 2.4 .0-test1 Linux kernel 2.4 |
| Not Vulnerable: |
Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.4.27 -pre5 Linux kernel 2.4.27 -pre4 Linux kernel 2.4.27 -pre3 Linux kernel 2.4.27 -pre2 Linux kernel 2.4.27 -pre1 |
Discussion
Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability
A vulnerability in the Linux kernel in the 64-bit file offset handling code may allow malicious users to read kernel memory. This issue is due to a design error that causes the affected code to fail to properly validate file pointers.
An attacker may leverage this issue to read arbitrary Linux kernel memory. This could allow an attacker to read sensitive data such as cached passwords. This issue will certainly aid in further attacks against the affected computer.
It has been reported that the Linux 2.6.X kernel, although still vulnerable, might not be exploitable. This BID will be updated when more information becomes available.
A vulnerability in the Linux kernel in the 64-bit file offset handling code may allow malicious users to read kernel memory. This issue is due to a design error that causes the affected code to fail to properly validate file pointers.
An attacker may leverage this issue to read arbitrary Linux kernel memory. This could allow an attacker to read sensitive data such as cached passwords. This issue will certainly aid in further attacks against the affected computer.
It has been reported that the Linux 2.6.X kernel, although still vulnerable, might not be exploitable. This BID will be updated when more information becomes available.
Exploit / POC
Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability
The following exploit has been provided by iSEC Security Research. This exploit is reported to trigger this issue on 2.4.X kernels and not 2.6.X kernels:
The following exploit has been provided by iSEC Security Research. This exploit is reported to trigger this issue on 2.4.X kernels and not 2.6.X kernels:
Solution / Fix
Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability
Solution:
SGI has made available Patch 10096 and advisory (20040804-01-U), correcting this and other vulnerabilities for systems running SGI ProPack 3.
Patch 10096 is available from:
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/
Please see the referenced advisory for further details regarding obtaining and applying appropriate updates.
RedHat Linux has released advisory FEDORA-2004-251 that addresses this issue for Fedora Core 1. Fedora users may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Trustix Secure Linux has released advisory TSLSA-2004-0041 to address this, and other issues. Please see the referenced advisory for further information.
Red Hat has released advisory RHSA-2004:418-05 and RHSA-2004:413-07 and fixes to address this and other issues on Red Hat Linux Enterprise 2.1 and 3.0 platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Red Hat Fedora has released advisory FEDORA-2004-247 along with fixes dealing with this issue. Please see the referenced advisory for further details.
SuSE has released advisory SUSE-SA:2004:024 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released advisory RHSA-2004:327-09 along with fixes to address this issue for Red Hat Enterprise Linux 2.1 for Itanium processors. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200408-24 to address this issue. Please see the attached advisory for further information on how to upgrade the kernel on Gentoo computers.
Mandrake has released an advisory (MDKSA-2004:087) to address this issue. Please see the referenced advisory for more information.
Conectiva has released an advisory (CLA-2004:879) to address this issue. Please see the referenced advisory for more information.
VMware has released an advisory dealing with this issue for their ESX Server virtual machine packages. Please see the Web reference for more information.
VMWare ESX Server 2.0.1
VMWare ESX Server 2.1.1
VMWare ESX Server 2.1.2
Linux kernel 2.4.18
Linux kernel 2.4.19
Linux kernel 2.4.21
Linux kernel 2.4.22
Linux kernel 2.4.25
Linux kernel 2.6.3
Linux kernel 2.6.4
Linux kernel 2.6.5
Solution:
SGI has made available Patch 10096 and advisory (20040804-01-U), correcting this and other vulnerabilities for systems running SGI ProPack 3.
Patch 10096 is available from:
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/
Please see the referenced advisory for further details regarding obtaining and applying appropriate updates.
RedHat Linux has released advisory FEDORA-2004-251 that addresses this issue for Fedora Core 1. Fedora users may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Trustix Secure Linux has released advisory TSLSA-2004-0041 to address this, and other issues. Please see the referenced advisory for further information.
Red Hat has released advisory RHSA-2004:418-05 and RHSA-2004:413-07 and fixes to address this and other issues on Red Hat Linux Enterprise 2.1 and 3.0 platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
Red Hat Fedora has released advisory FEDORA-2004-247 along with fixes dealing with this issue. Please see the referenced advisory for further details.
SuSE has released advisory SUSE-SA:2004:024 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released advisory RHSA-2004:327-09 along with fixes to address this issue for Red Hat Enterprise Linux 2.1 for Itanium processors. Please see the referenced advisory for further information.
Gentoo has released advisory GLSA 200408-24 to address this issue. Please see the attached advisory for further information on how to upgrade the kernel on Gentoo computers.
Mandrake has released an advisory (MDKSA-2004:087) to address this issue. Please see the referenced advisory for more information.
Conectiva has released an advisory (CLA-2004:879) to address this issue. Please see the referenced advisory for more information.
VMware has released an advisory dealing with this issue for their ESX Server virtual machine packages. Please see the Web reference for more information.
VMWare ESX Server 2.0.1
-
VMWare esx-2.0.1-11429-upgrade.tar.gz
http://vmware-svca.www.conxion.com/secured/esx/esx-2.0.1-11429-upgrade .tar.gz
VMWare ESX Server 2.1.1
-
VMWare esx-2.1.2-10921-upgrade.tar.gz
http://vmware-svca.www.conxion.com/secured/esx/esx-2.1.2-10921-upgrade .tar.gz
VMWare ESX Server 2.1.2
-
VMWare esx-2.1.2-10921-upgrade.tar.gz
http://vmware-svca.www.conxion.com/secured/esx/esx-2.1.2-10921-upgrade .tar.gz
Linux kernel 2.4.18
-
Mandrake kernel-secure-2.4.19.44mdk-1-1mdk.i586.rpm
Mandrake Multi Network Firewall 8.2
http://www.mandrakesecure.net/en/ftp.php -
SuSE k_deflt-2.4.18-310.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/images/k_deflt-2.4.18-310. i386.rpm -
SuSE k_i386-2.4.18-310.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/images/k_i386-2.4.18-310.i 386.rpm -
SuSE k_psmp-2.4.18-310.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/images/k_psmp-2.4.18-310.i 386.rpm -
SuSE k_smp-2.4.18-310.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/images/k_smp-2.4.18-310.i3 86.rpm -
SuSE kernel-source-2.4.18.SuSE-310.i386.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.0/d3/kernel-source-2.4.18.Su SE-310.i386.rpm
Linux kernel 2.4.19
-
Mandrake kernel-2.4.19.44mdk-1-1mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.4.19.44mdk-1-1mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.4.19.44mdk-1-1mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.4.19.44mdk-1-1mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.4.19.44mdk-1-1mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.19.44mdk-1-1mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.19.44mdk-1-1mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.19-44mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.19-44mdk.x86_64.rpm
Mandrake Corporate Server 2.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
SuSE k_athlon-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/k_athlon-2.4.21-2 38.i586.rpm -
SuSE k_deflt-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/k_deflt-2.4.21-23 8.i586.rpm -
SuSE k_psmp-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/k_psmp-2.4.21-238 .i586.rpm -
SuSE k_smp-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/k_smp-2.4.21-238. i586.rpm -
SuSE kernel-source-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/kernel-source-2.4 .21-238.i586.rpm
Linux kernel 2.4.21
-
Mandrake kernel-2.4.21.0.33mdk-1-1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.4.21.0.33mdk-1-1mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.4.21.0.33mdk-1-1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.4.21.0.33mdk-1-1mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.4.21.0.33mdk-1-1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.21.0.33mdk-1-1mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.21.0.33mdk-1-1mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.21-0.33mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.21-0.33mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
SuSE k_athlon-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_athlon-2.4.21-2 38.i586.rpm -
SuSE k_deflt-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_deflt-2.4.21-23 8.i586.rpm -
SuSE k_deflt-2.4.21-238.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/k_deflt-2.4.2 1-238.x86_64.rpm -
SuSE k_smp-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_smp-2.4.21-238. i586.rpm -
SuSE k_smp-2.4.21-238.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/k_smp-2.4.21- 238.x86_64.rpm -
SuSE k_smp4G-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_smp4G-2.4.21-23 8.i586.rpm -
SuSE k_um-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_um-2.4.21-238.i 586.rpm -
SuSE kernel-source-2.4.21-238.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/kernel-source-2.4 .21-238.i586.rpm -
SuSE kernel-source-2.4.21-238.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/kernel-source -2.4.21-238.x86_64.rpm
Linux kernel 2.4.22
-
Mandrake kernel-2.4.22.37mdk-1-1mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.4.22.37mdk-1-1mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.4.22.37mdk-1-1mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-i686-up-4GB-2.4.22.37mdk-1-1mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-p3-smp-64GB-2.4.22.37mdk-1-1mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.4.22.37mdk-1-1mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.4.22.37mdk-1-1mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.22.37mdk-1-1mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.22.37mdk-1-1mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.22-37mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.22-37mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
RedHat kernel-2.4.22-1.2199.nptl.athlon.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-2.4.22-1.2199.nptl.i586.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-2.4.22-1.2199.nptl.i686.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-2.4.22-1.2199.nptl.x86_64.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-BOOT-2.4.22-1.2199.nptl.i386.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-debuginfo-2.4.22-1.2199.nptl.athlon.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-debuginfo-2.4.22-1.2199.nptl.i386.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-debuginfo-2.4.22-1.2199.nptl.i586.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-debuginfo-2.4.22-1.2199.nptl.i686.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-debuginfo-2.4.22-1.2199.nptl.x86_64.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-doc-2.4.22-1.2199.nptl.i386.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-doc-2.4.22-1.2199.nptl.x86_64.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-smp-2.4.22-1.2199.nptl.athlon.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-smp-2.4.22-1.2199.nptl.i586.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-smp-2.4.22-1.2199.nptl.i686.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-smp-2.4.22-1.2199.nptl.x86_64.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-source-2.4.22-1.2199.nptl.i386.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
RedHat kernel-source-2.4.22-1.2199.nptl.x86_64.rpm
Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/
Linux kernel 2.4.25
-
Mandrake kernel-2.4.25.8mdk-1-1mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.4.25.8mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.4.25.8mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-i686-up-4GB-2.4.25.8mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-p3-smp-64GB-2.4.25.8mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.25.8mdk-1-1mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.4.25.8mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.25-8mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.4.25-8mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Linux kernel 2.6.3
-
Mandrake kernel-2.6.3.16mdk-1-1mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-2.6.3.16mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-enterprise-2.6.3.16mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-i686-up-4GB-2.6.3.16mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-p3-smp-64GB-2.6.3.16mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.6.3.16mdk-1-1mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-secure-2.6.3.16mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.6.3.16mdk-1-1mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-smp-2.6.3.16mdk-1-1mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.6.3-16mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-2.6.3-16mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-stripped-2.6.3-16mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake kernel-source-stripped-2.6.3-16mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Linux kernel 2.6.4
-
SuSE kernel-bigsmp-2.6.5-7.104.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6 .5-7.104.i586.rpm -
SuSE kernel-default-2.6.5-7.104.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2. 6.5-7.104.i586.rpm -
SuSE kernel-smp-2.6.5-7.104.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5- 7.104.i586.rpm -
SuSE kernel-source-2.6.5-7.104.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-source-2.6 .5-7.104.i586.rpm -
SuSE kernel-source-2.6.5-7.104.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-source -2.6.5-7.104.x86_64.rpm -
SuSE kernel-syms-2.6.5-7.104.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-syms-2.6.5 -7.104.i586.rpm
Linux kernel 2.6.5
-
RedHat kernel-2.6.7-1.494.2.2.i586.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-2.6.7-1.494.2.2.i686.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-2.6.7-1.494.2.2.x86_64.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-debuginfo-2.6.7-1.494.2.2.i586.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-debuginfo-2.6.7-1.494.2.2.i686.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-debuginfo-2.6.7-1.494.2.2.x86_64.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-doc-2.6.7-1.494.2.2.noarch.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-smp-2.6.7-1.494.2.2.i586.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-smp-2.6.7-1.494.2.2.i686.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-smp-2.6.7-1.494.2.2.x86_64.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
RedHat kernel-sourcecode-2.6.7-1.494.2.2.noarch.rpm
Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
References
Linux Kernel File 64-Bit Offset Pointer Handling Kernel Memory Disclosure Vulnerability
References:
References:
- RHSA-2004:327-09 - Updated Itanium kernel packages resolve security issues (RedHat)
- RHSA-2004:413-07 - Updated kernel packages fix security vulnerabilities (RedHat)
- RHSA-2004:418-05 - Updated kernel packages fix security issues (RedHat)
- VMware ESX Server 1.5.2 Patch 6 Security Update (VMware)
- VMware ESX Server 2.0.1 Patch 1 Security Update (for 2.0.x systems) (VMware)
- VMware ESX Server 2.1.2 Security Update (for 2.1.x systems) (VMware)
- Linux kernel file offset pointer races (Paul Starzetz
)