Linux kernel do_fork()系统调用内存泄露漏洞

漏洞信息详情

Linux kernel do_fork()系统调用内存泄露漏洞

漏洞简介

Linux是一款开放源代码操作系统。
Linux包含的do_fork()函数包含一个错误路径,本地攻击者可以利用这个漏洞获得部分内存敏感信息。
目前没有详细漏洞细节提供。

漏洞公告

厂商补丁:
MandrakeSoft
————
MandrakeSoft已经为此发布了一个安全公告(MDKSA-2004:037)以及相应补丁:

MDKSA-2004:037:Updated kernel packages fix multiple vulnerabilities

链接:http://www.linux-mandrake.com/en/security/2004/2004-037.php” target=”_blank”>
http://www.linux-mandrake.com/en/security/2004/2004-037.php

补丁下载:

Updated Packages:

Mandrakelinux 10.0:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-2.4.25.4mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-2.6.3.9mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-enterprise-2.4.25.4mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-enterprise-2.6.3.9mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-i686-up-4GB-2.4.25.4mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-i686-up-4GB-2.6.3.9mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-p3-smp-64GB-2.4.25.4mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-p3-smp-64GB-2.6.3.9mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-secure-2.6.3.9mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-smp-2.4.25.4mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-smp-2.6.3.9mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-source-2.4.25-4mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-source-2.6.3-9mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/RPMS/kernel-source-stripped-2.6.3-9mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/SRPMS/kernel-2.4.25.4mdk-1-1mdk.src.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/10.0/SRPMS/kernel-2.6.3.9mdk-1-1mdk.src.rpm

Corporate Server 2.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kernel-2.4.19.40mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kernel-enterprise-2.4.19.40mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kernel-secure-2.4.19.40mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kernel-smp-2.4.19.40mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/RPMS/kernel-source-2.4.19-40mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/corporate/2.1/SRPMS/kernel-2.4.19.40mdk-1-1mdk.src.rpm

Corporate Server 2.1/x86_64:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/kernel-2.4.19.41mdk-1-1mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/kernel-secure-2.4.19.41mdk-1-1mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/kernel-smp-2.4.19.41mdk-1-1mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/RPMS/kernel-source-2.4.19-41mdk.x86_64.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/SRPMS/kernel-2.4.19.40mdk-1-1mdk.src.rpm

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/x86_64/corporate/2.1/SRPMS/kernel-2.4.19.41mdk-1-1mdk.src.rpm

Mandrakelinux 9.1:

ftp://download.sourceforge.net/pub/mirrors/mandrake/updates/9.1/RPMS/kernel-2.4.21.0.30mdk-1-1mdk.i586.rpm

ftp://download.sourceforge.net/pub/mirror


参考网址

来源: MLIST
名称: [linux-kernel] 20040408 [PATCH]: 2.4/2.6 do_fork() error path memory leak
链接:http://marc.theaimsgroup.com/?l=linux-kernel&m=108139073506983&w=2

来源: SGI
名称: 20040505-01-U
链接:ftp://patches.sgi.com/support/free/security/advisories/20040505-01-U.asc

来源: SGI
名称: 20040504-01-U
链接:ftp://patches.sgi.com/support/free/security/advisories/20040504-01-U.asc

来源: REDHAT
名称: RHSA-2004:255
链接:http://www.redhat.com/support/errata/RHSA-2004-255.html

来源: SUSE
名称: SuSE-SA:2004:010
链接:http://www.novell.com/linux/security/advisories/2004_10_kernel.html

来源: GENTOO
名称: GLSA-200407-02
链接:http://security.gentoo.org/glsa/glsa-200407-02.xml

来源: OVAL
名称: oval:org.mitre.oval:def:10297
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10297

来源: linux.bkbits.net:8080
链接:http://linux.bkbits.net:8080/linux-2.6/cset@407b1217x4jtqEkpFW2g_-RcF0726A

来源: linux.bkbits.net:8080
链接:http://linux.bkbits.net:8080/linux-2.4/cset@407bf20eDeeejm8t36_tpvSE-8EFHA

来源: FEDORA
名称: FEDORA-2004-111
链接:http://fedoranews.org/updates/FEDORA-2004-111.shtml

来源: CONECTIVA
名称: CLA-2004:846
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000846

来源: XF
名称: linux-dofork-memory-leak(16002)
链接:http://xforce.iss.net/xforce/xfdb/16002

来源: TURBO
名称: TLSA-2004-14
链接:http://www.turbolinux.com/security/2004/TLSA-2004-14.txt

来源: BID
名称: 10221
链接:http://www.securityfocus.com/bid/10221

来源: REDHAT
名称: RHSA-2004:327
链接:http://www.redhat.com/support/errata/RHSA-2004-327.html

来源: REDHAT
名称: RHSA-2004:260
链接:http://www.redhat.com/support/errata/RHSA-2004-260.html

来源: MANDRAKE
名称: MDKSA-2004:037
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2004:037

来源: DEBIAN
名称: DSA-1082
链接:http://www.debian.org/security/2006/dsa-1082

来源: DEBIAN
名称: DSA-1070
链接:http://www.debian.org/security/2006/dsa-1070

来源: DEBIAN
名称: DSA-1069
链接:http://www.debian.org/security/2006/dsa-1069

来源: DEBIAN
名称: DSA-1067
链接:http://www.debian.org/security/2006/dsa-1067

来源: CIAC
名称: O-164
链接:http://www.ciac.org/ciac/bulletins/o-164.shtml

来源: SECUNIA
名称: 20338
链接:http://secunia.com/advisories/20338

来源: SECUNIA
名称: 20202
链接:http://secunia.com/advisories/20202

来源: SECUNIA
名称: 20163
链接:http://secunia.com/advisories/20163

来源: SECUNIA
名称: 20162
链接:http://secunia.com/advisories/20162

来源: SECUNIA
名称: 11892
链接:http://secunia.com/advisories/11892

来源: SECUNIA
名称: 11891
链接:http://secunia.com/advisories/11891

来源: SECUNIA
名称: 11861
链接:http://secunia.com/advisories/11861

来源: SECUNIA
名称: 11541
链接:http://secunia.com/advisories/11541

来源: SECUNIA
名称: 11486
链接:http://secunia.com/advisories/11486

来源: SECUNIA
名称: 11464
链接:http://secunia.com/advisories/11464

来源: SECUNIA
名称: 11429
链接:http://secunia.com/advisories/11429

来源: US Government Resource: oval:org.mitre.oval:def:2819
名称: oval:org.mitre.oval:def:2819
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2819

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享