Linux Kernel Audit Subsystem Local Denial Of Service Vulnerability
BID:12309
Info
Linux Kernel Audit Subsystem Local Denial Of Service Vulnerability
| Bugtraq ID: | 12309 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-1237 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 19 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 Linux kernel 2.6.10 rc2 Linux kernel 2.6.10 Linux kernel 2.6.9 Linux kernel 2.6.8 rc3 Linux kernel 2.6.8 rc2 Linux kernel 2.6.8 rc1 Linux kernel 2.6.8 Linux kernel 2.6.7 rc1 Linux kernel 2.6.7 Linux kernel 2.6.6 rc1 Linux kernel 2.6.6 Linux kernel 2.6.5 Linux kernel 2.6.4 Linux kernel 2.6.3 Linux kernel 2.6.2 Linux kernel 2.6.1 -rc2 Linux kernel 2.6.1 -rc1 Linux kernel 2.6.1 Linux kernel 2.6 .10 Linux kernel 2.6 -test9-CVS Linux kernel 2.6 -test9 Linux kernel 2.6 -test8 Linux kernel 2.6 -test7 Linux kernel 2.6 -test6 Linux kernel 2.6 -test5 Linux kernel 2.6 -test4 Linux kernel 2.6 -test3 Linux kernel 2.6 -test2 Linux kernel 2.6 -test11 Linux kernel 2.6 -test10 Linux kernel 2.6 -test1 Linux kernel 2.6 Linux kernel 2.4.29 -rc2 Linux kernel 2.4.29 -rc1 Linux kernel 2.4.28 Linux kernel 2.4.27 -pre5 Linux kernel 2.4.27 -pre4 Linux kernel 2.4.27 -pre3 Linux kernel 2.4.27 -pre2 Linux kernel 2.4.27 -pre1 Linux kernel 2.4.27 Linux kernel 2.4.26 Linux kernel 2.4.25 Linux kernel 2.4.24 -ow1 Linux kernel 2.4.24 Linux kernel 2.4.23 -pre9 Linux kernel 2.4.23 -ow2 Linux kernel 2.4.23 Linux kernel 2.4.22 Linux kernel 2.4.21 pre7 Linux kernel 2.4.21 pre4 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.4.20 Linux kernel 2.4.19 -pre6 Linux kernel 2.4.19 -pre5 Linux kernel 2.4.19 -pre4 Linux kernel 2.4.19 -pre3 Linux kernel 2.4.19 -pre2 Linux kernel 2.4.19 -pre1 Linux kernel 2.4.19 Linux kernel 2.4.18 pre-8 Linux kernel 2.4.18 pre-7 Linux kernel 2.4.18 pre-6 Linux kernel 2.4.18 pre-5 Linux kernel 2.4.18 pre-4 Linux kernel 2.4.18 pre-3 Linux kernel 2.4.18 pre-2 Linux kernel 2.4.18 pre-1 Linux kernel 2.4.18 x86 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 .0-test9 Linux kernel 2.4 .0-test8 Linux kernel 2.4 .0-test7 Linux kernel 2.4 .0-test6 Linux kernel 2.4 .0-test5 Linux kernel 2.4 .0-test4 Linux kernel 2.4 .0-test3 Linux kernel 2.4 .0-test2 Linux kernel 2.4 .0-test12 Linux kernel 2.4 .0-test11 Linux kernel 2.4 .0-test10 Linux kernel 2.4 .0-test1 Linux kernel 2.4 |
| Not Vulnerable: | |
Discussion
Linux Kernel Audit Subsystem Local Denial Of Service Vulnerability
An unspecified local denial of service vulnerability is reported to affect the system call filtering code in the audit subsystem of the Linux kernel.
Originally, it was believed that this vulnerability was isolated to the kernel that is distributed with Red Hat Enterprise Linux. This is not the case and this BID is updated accordingly.
An unspecified local denial of service vulnerability is reported to affect the system call filtering code in the audit subsystem of the Linux kernel.
Originally, it was believed that this vulnerability was isolated to the kernel that is distributed with Red Hat Enterprise Linux. This is not the case and this BID is updated accordingly.
Exploit / POC
Linux Kernel Audit Subsystem Local Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Linux Kernel Audit Subsystem Local Denial Of Service Vulnerability
Solution:
SuSE has released a security announcement (SUSE-SA:2005:003) and fixes to address the vulnerability described in this BID and also other vulnerabilities. Customers are advised to peruse the referenced announcement for further details in regard to obtaining and applying appropriate fixes.
Red Hat has released advisory RHSA-2005:043-13 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
SuSE has released security advisory SUSE-SA:2005:010 dealing with an issue that has arisen due to a broken patch previously released. Apparently due to various new checks being performed computers running an NVidia graphics card may experience a denial of service condition when X Windows is started. This issue affects SuSE Linux 9.1, SuSE Linux Enterprise Server 9, and Novell Linux Desktop 9.
Linux kernel 2.4.21
Linux kernel 2.6.4
Linux kernel 2.6.8
Solution:
SuSE has released a security announcement (SUSE-SA:2005:003) and fixes to address the vulnerability described in this BID and also other vulnerabilities. Customers are advised to peruse the referenced announcement for further details in regard to obtaining and applying appropriate fixes.
Red Hat has released advisory RHSA-2005:043-13 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
SuSE has released security advisory SUSE-SA:2005:010 dealing with an issue that has arisen due to a broken patch previously released. Apparently due to various new checks being performed computers running an NVidia graphics card may experience a denial of service condition when X Windows is started. This issue affects SuSE Linux 9.1, SuSE Linux Enterprise Server 9, and Novell Linux Desktop 9.
Linux kernel 2.4.21
-
SuSE k_athlon-2.4.21-273.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_athlon-2.4.21-2 73.i586.rpm -
SuSE k_deflt-2.4.21-273.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_deflt-2.4.21-27 3.i586.rpm -
SuSE k_deflt-2.4.21-273.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/k_deflt-2.4.2 1-273.x86_64.rpm -
SuSE k_smp-2.4.21-273.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_smp-2.4.21-273. i586.rpm -
SuSE k_smp-2.4.21-273.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/k_smp-2.4.21- 273.x86_64.rpm -
SuSE k_smp4G-2.4.21-273.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_smp4G-2.4.21-27 3.i586.rpm -
SuSE k_um-2.4.21-273.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/k_um-2.4.21-273.i 586.rpm -
SuSE kernel-source-2.4.21-273.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/kernel-source-2.4 .21-273.i586.rpm -
SuSE kernel-source-2.4.21-273.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/kernel-source -2.4.21-273.x86_64.rpm
Linux kernel 2.6.4
-
SuSE kernel-bigsmp-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-bigsmp-2.6 .5-7.147.i586.rpm -
SuSE kernel-default-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-default-2. 6.5-7.147.i586.rpm -
SuSE kernel-default-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-defaul t-2.6.5-7.147.x86_64.rpm -
SuSE kernel-docs-2.6.5-7.147.noarch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/noarch/kernel-docs-2.6 .5-7.147.noarch.rpm -
SuSE kernel-smp-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-smp-2.6.5- 7.147.i586.rpm -
SuSE kernel-smp-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-smp-2. 6.5-7.147.x86_64.rpm -
SuSE kernel-source-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-source-2.6 .5-7.147.i586.rpm -
SuSE kernel-source-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-source -2.6.5-7.147.x86_64.rpm -
SuSE kernel-syms-2.6.5-7.147.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/kernel-syms-2.6.5 -7.147.i586.rpm -
SuSE kernel-syms-2.6.5-7.147.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/kernel-syms-2 .6.5-7.147.x86_64.rpm -
SuSE ltmodem-2.6.2-38.13.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/ltmodem-2.6.2-38. 13.i586.rpm
Linux kernel 2.6.8
-
SuSE kernel-bigsmp-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-bigsmp-2.6 .8-24.11.i586.rpm -
SuSE kernel-default-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-default-2. 6.8-24.11.i586.rpm -
SuSE kernel-default-2.6.8-24.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/kernel-defaul t-2.6.8-24.11.x86_64.rpm -
SuSE kernel-smp-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-smp-2.6.8- 24.11.i586.rpm -
SuSE kernel-smp-2.6.8-24.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/kernel-smp-2. 6.8-24.11.x86_64.rpm -
SuSE kernel-source-2.6.8-24.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/kernel-source-2.6 .8-24.11.i586.rpm -
SuSE kernel-source-2.6.8-24.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/kernel-source -2.6.8-24.11.x86_64.rpm
References
Linux Kernel Audit Subsystem Local Denial Of Service Vulnerability
References:
References: