Multiple local security vulnerabilities in Linux Kernel Econet
Release date:
Updated on:
Affected Systems:
Debian Linux 5.0 x
Linux kernel 2.6.0-2.6.36
Linux kernel 2.6.0-2.6.26
Ubuntu Linux 9.10-10.04
Unaffected system:
Linux kernel 2.6.37-rc2
Linux kernel 2.6.37-rc2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45072
Cve id: CVE-2010-3848, CVE-2010-3849, CVE-2010-3850
Linux Kernel is the Kernel used by open source Linux.
Multiple local vulnerabilities exist in the Econet protocol implementation of Linux Kernel. Local attackers can exploit these vulnerabilities to bypass certain security restrictions, resulting in denial of service or use Kernel-level permissions to execute arbitrary code.
<* Source: Dan Rosenberg
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Debian
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.debian.org/security/
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.kernel.org/