| | |
Debian releases fix for Linux kernel 2.6.8 vulnerabilities
As reported here last week, three security flaws had been discovered that impacted upon the 2.6.x Kernel. A NULL-pointer dereference within netfilter when handling SCTP connections with unknown chunk types that could be exploited to crash the kernel; a cpuset_task_read() function in /kernel/cpuset.c which had an underflow error that could potentially be exploited in order to read the kernel memory; and a problem whereby the kernel itself mishandled seeds for random number generation, potentially weakening application security for those programs relying upon secure random number generation.
Well according to the debian.org mailing list these have now been fixed with the release of numerous updates for Linux kernel 2.6.8 as detailed in Debian Security Advisory DSA 1304-1.
The latest update also fixes a number of other problems, such as the regression in the smbfs subsystem introduced in DSA-1233 causing symlinks to be interpreted as regular files.
Debian recommend that you upgrade your kernel package immediately and reboot the machine, and if you have built a custom kernel from the kernel source package that you rebuild to take advantage of the new fixes.
Just to help, the upgrade instructions are:
wget url (to fetch the file for you)
dpkg -i file.deb (to install the referenced file)
And for those of you using the apt-get package manager:
apt-get update (to update the internal database)
apt-get upgrade (to install corrected packages)
Well according to the debian.org mailing list these have now been fixed with the release of numerous updates for Linux kernel 2.6.8 as detailed in Debian Security Advisory DSA 1304-1.
The latest update also fixes a number of other problems, such as the regression in the smbfs subsystem introduced in DSA-1233 causing symlinks to be interpreted as regular files.
Debian recommend that you upgrade your kernel package immediately and reboot the machine, and if you have built a custom kernel from the kernel source package that you rebuild to take advantage of the new fixes.
Just to help, the upgrade instructions are:
wget url (to fetch the file for you)
dpkg -i file.deb (to install the referenced file)
And for those of you using the apt-get package manager:
apt-get update (to update the internal database)
apt-get upgrade (to install corrected packages)
0
•
•
•
•
My computer systems usually has problems with Kernell dll.32, which causes my system to crash.
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
http://www.1-satellite-tv-facts.com
http://www.1-satellite-tv-facts.com/Direct-TV.html
http://www.1-satellite-tv-facts.com/Dish-Network.html
http://www.1-satellite-tv-facts.com/...ite-Radio.html
http://www.1-satellite-tv-facts.com/...t-Service.html
http://www.1-satellite-tv-facts.com/Satellite-DSL.html
http://www.1-satellite-tv-facts.com/...-Internet.html
http://www.1-satellite-tv-facts.com/VoIP.html
http://www.1-satellite-tv-facts.com/Phone-Systems.html
http://www.1-satellite-tv-facts.com/...-Programs.html
Similar Threads
- News Story: Linux Kernel 2.6.x vulnerabilities (Network Security)
- Debian releases a Windows-based installer (Getting Started and Choosing a Distro)
- Debian linux c++ development (*nix Software)
- Tutorial: Installing Debian Linux (3.1) (Getting Started and Choosing a Distro)
- Linux Debian Dual Boot (*nix Software)
| Thread Tools | Search this Thread |
advertising age amd android apple avatar bluegene botnet browser business cellphone china chips copyright crime data database dell desktop development distributions dos downloads economy email encryption energy enterprise facebook firefox gadgets games gaming google government hacker hacking hardware ibm ibm.news intelibm internet iphone ipod itunes law linux mac malware marketing medicine memory microsoft mobile mozilla music news novell openoffice opensource operatingsystems os pc piracy porn privacy ps3 recession redhat research russia search security sex socialnetworking software spam sun supercomputer supercomputing survey technology trends trojan twitter ubuntu uk unix video virtualization virus vista vmware web windows windows7 working x86 xbox youtube




