Please support our Tech Talk advertiser: Programming Forums
Jun 17th, 2007, 11:38 am
As reported here last week, three security flaws had been discovered that impacted upon the 2.6.x Kernel. A NULL-pointer dereference within netfilter when handling SCTP connections with unknown chunk types that could be exploited to crash the kernel; a cpuset_task_read() function in /kernel/cpuset.c which had an underflow error that could potentially be exploited in order to read the kernel memory; and a problem whereby the kernel itself mishandled seeds for random number generation, potentially weakening application security for those programs relying upon secure random number generation.
Well according to the debian.org mailing list these have now been fixed with the release of numerous updates for Linux kernel 2.6.8 as detailed in Debian Security Advisory DSA 1304-1.
The latest update also fixes a number of other problems, such as the regression in the smbfs subsystem introduced in DSA-1233 causing symlinks to be interpreted as regular files.
Debian recommend that you upgrade your kernel package immediately and reboot the machine, and if you have built a custom kernel from the kernel source package that you rebuild to take advantage of the new fixes.
Just to help, the upgrade instructions are:
wget url (to fetch the file for you)
dpkg -i file.deb (to install the referenced file)
And for those of you using the apt-get package manager:
apt-get update (to update the internal database)
apt-get upgrade (to install corrected packages)
Well according to the debian.org mailing list these have now been fixed with the release of numerous updates for Linux kernel 2.6.8 as detailed in Debian Security Advisory DSA 1304-1.
The latest update also fixes a number of other problems, such as the regression in the smbfs subsystem introduced in DSA-1233 causing symlinks to be interpreted as regular files.
Debian recommend that you upgrade your kernel package immediately and reboot the machine, and if you have built a custom kernel from the kernel source package that you rebuild to take advantage of the new fixes.
Just to help, the upgrade instructions are:
wget url (to fetch the file for you)
dpkg -i file.deb (to install the referenced file)
And for those of you using the apt-get package manager:
apt-get update (to update the internal database)
apt-get upgrade (to install corrected packages)
This blog entry was written by Bill Andad, staff writer aka newsguy. It has received 3,619 views, 1 comment, and 22 linkbacks. 2 voters have rated this entry an average of 5 out of 5 stars. It was promoted to featured status Jun 17th, 2007.
•
•
•
•
advertising apple botnet browser business china crime data desktop development email facebook firefox forensic gaming google hacking hardware ibm internet iphone ipod law legal linux malware microsoft mobile news novell open source privacy red hat research search security software spam survey technology trojan ubuntu uk virtualization virus vista web windows yahoo youtube
All Recent Tags Comments (Newest First)
docsharp01 | Newbie Poster | Jul 1st, 2008
•
•
•
•
My computer systems usually has problems with Kernell dll.32, which causes my system to crash.
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
Post Comment
•
•
•
•
Only community members can start a blog or comment on blog entries. You must register or log in to contribute.
•
•
•
•
•
•
•
•
DaniWeb Tech Talk Marketplace
Related Blog Entries
- One Mega Computer To Run every Computer? (18 Hours Ago)
- 168 million domain names (1 Day Ago)
- Brit kids go hack to school (3 Days Ago)
- How much data does your iPhone move in a month? (3 Days Ago)
- Shock Horror: IE8 BETA 2 has some bugs (5 Days Ago)
- It's True -- Some People Want You Kept in the Dark (8 Days Ago)
- Virtual physios to soothe stroke recovery (9 Days Ago)
- AMDS Gloomy Future. (9 Days Ago)
- Don't Allow Security Breaches to Rip Your Britches (11 Days Ago)
- Four letters, 8 points, describes Scrabulous (11 Days Ago)
Related Forum Threads
- How to install a Debian LAMP Server (PHP)
- RedHat 8 (*nix Software)
- What's better? Windows 2000 Server or Linux Server? (Windows Servers and IIS)
- linux FFS kernel support (Getting Started and Choosing a Distro)
- SoundMAx SoundCard in Debian Sarge (*nix Hardware Configuration)
- 1000% Speed Increase Using Linux Kernel 2.6 (Kernels and Modules)
- Switched to Linux 2 Months Ago (Getting Started and Choosing a Distro)
- Linux on Mac (Getting Started and Choosing a Distro)
- Tutorials for Linux (*nix Software)
- Why Novell will beat Linux (Novell)
Featured Entry