Linux Kernel 2.4 XDR数据包处理NFSv3远程服务拒绝漏洞

漏洞信息详情

Linux Kernel 2.4 XDR数据包处理NFSv3远程服务拒绝漏洞

漏洞简介

Linux kernel 2.4.21之前版本的nfs3xdr.c的decode_fh函数中存在整数符号错误漏洞。远程攻击者可以借助NFSv3进程调用的XDR数据中的负值导致服务拒绝(内核恐慌)。

漏洞公告

SuSE has released advisory SUSE-SA:2004:035 mainly to address the vulnerability described in BID 11281. However, in the addendum of this advisory, it is reported that fixes for the issues described in this BID are now available on the SuSE update FTP server for download. Customers are advised to see the referenced advisory for further information regarding obtaining and applying appropriate updates.
Debian has released advisory DSA 358-4 to address this issue.
Red Hat has released an advisory (RHSA-2003:198-16) containing updated IA64 fixes for Red Hat Enterprise Linux AS (v. 2.1) and Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor. These fixes are only available through the Red Hat Network which can be found at
http://rhn.redhat.com/.
Red Hat has also released an advisory (RHSA-2003-239) containing kernel fixes for Red Hat Enterprise Linux AS, ES, and WS(v. 2.1). These fixes are also only available through the Red Hat Network which can be found at
http://rhn.redhat.com/.
Red Hat security advisory RHSA-2003:172-27 has been released to address this and other issues. However, this advisory is superceded by RHBA-2003:263-05, which addresses unrelated bugs but provides Kernel updates that include more recent fixes for this and other security vulnerabilities.
Conectiva has released a security advisory (CLSA-2003:730) containing fixes to address this issue in CLEE 1.0. Users are advised to upgrade as soon as possible.
Conectiva has released a security advisory (CLA-2003:796) containing fixes to address this issue in Conectiva Linux 8.
SuSE has released advisory SUSE-SA:2004:028 along with fixes dealing with this issue. Please see the referenced advisory for more information.
SuSE has released a second advisory dealing with this issue. Apparently the kernel shipped with SuSE Linux versions 8.1, 8.2, and 9.0 were not patched for this issue. Please see the referenced advisory for more information.
RedHat kernel-2.4.18-3.i686.rpm

RedHat kernel-2.4.2-2.i386.rpm

RedHat kernel-source-2.4.18-14.i386.rpm

RedHat kernel-bigmem-2.4.18-14.i686.rpm

RedHat kernel-BOOT-2.4.7-10.i386.rpm

RedHat kernel-doc-2.4.2-2.i386.rpm

RedHat kernel-2.4.20-8.athlon.rpm

RedHat kernel-source-2.4.2-2.i386.rpm

RedHat kernel-2.4.7-10.athlon.rpm

RedHat kernel-doc-2.4.18-3.i386.rpm

RedHat kernel-BOOT-2.4.20-8.i386.rpm

RedHat kernel-2.4.20-8.i586.rpm

RedHat kernel-2.4.7-10.i686.rpm

RedHat kernel-bigmem-2.4.20-8.i686.rpm

RedHat kernel-source-2.4.20-8.i386.rpm

RedHat kernel-2.4.20-8.i686.rpm

RedHat kernel-BOOT-2.4.18-3.i386.rpm

RedHat kernel-doc-2.4.18-14.i386.rpm

RedHat kernel-BOOT-2.4.2-2.i386.rpm

参考网址

来源: REDHAT
名称: RHSA-2003:198
链接:http://www.redhat.com/support/errata/RHSA-2003-198.html

来源: DEBIAN
名称: DSA-358
链接:http://www.debian.org/security/2004/dsa-358

来源: BUGTRAQ
名称: 20030729 Remote Linux Kernel < 2.4.21 DoS in XDR routine.
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105950927708272&w=2

来源: REDHAT
名称: RHSA-2003:239
链接:http://www.redhat.com/support/errata/RHSA-2003-239.html

来源: US Government Resource: oval:org.mitre.oval:def:386
名称: oval:org.mitre.oval:def:386
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:386

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享