|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Mandrake Local Security Checks >> MDKSA-2003:038: kernel Vulnerability Assessment Details
|
MDKSA-2003:038: kernel |
||
Check for the version of the kernel package Detailed Explanation for this Vulnerability Assessment The remote host is missing the patch for the advisory MDKSA-2003:038 (kernel). A bug in the kernel module loader code could permit a local user to gain root rights. This is done by a local user using ptrace and attaching to a modprobe process that is spawned if the user triggers the loading of a kernel module. A temporary workaround can be used to defend against this flaw. It is possible to temporarily disable the kmod kernel module loading subsystem in the kernel after all of the required kernel modules have been loaded. Be sure that you do not need to load additional kernel modules after implementing this workaround. To use it, as root execute: echo /no/such/file >/proc/sys/kernel/modprobe To automate this, you may wish to add it as the last line of the /etc/rc.d/rc.local file. You can revert this change by replacing the content '/sbin/modprobe' in the /proc/sys/kernel/modprobe file. The root user can still manually load kernel modules with this workaround in place. This update applies a patch to correct the problem. All users should upgrade. Please note that the Mandrake Linux 9.1 kernel already has this patch, and an updated kernel for Mandrake Linux 8.2 will be available shortly. For instructions on how to upgrade your kernel in Mandrake Linux, please refer to: http://www.mandrakesecure.net/en/kernelupdate.php Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2003:038 Network Security Threat Level: High Networks Security ID: 7112 Vulnerability Assessment Copyright: This script is Copyright (C) 2004 Tenable Network Security |
||
Cables, Connectors |
$1399.99
Cisco IP Phone 6841 – CP-6841-3PW-NA-K9=
$75.00
$759.99
Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24
$117.00
Cisco Catalyst WS-C2960-48TT-L V02 48 Port Fast Ethernet Switch
$34.00
Cisco WS-C3850-48P-L 48-Port Gigabit 3850 PoE Switch w/ 715W+ C3850-NM-4-1G Mod
$83.00
Cisco C3850-NM-2-10G 2 Port Network Exp.Module for 3850
$38.99
Cisco Catalyst 2960-L Series WS-C2960L-8PS-LL 8 Port PoE Switch
$108.00
LOT OF 20 Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module
$89.00
Cisco Catalyst WS-C3650-48TS-S 4X1G 3650 Series GE Network Switch
$450.00
|
||
No Discussions have been posted on this vulnerability. |