SB2006082201 - Improper input validation in Linux kernel
Published: August 22, 2006
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2006-4093)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the 'HID0 attention enable on PPC970 at boot time.' Upgrade to Linux Kernel version 2.4.33.1
Remediation
Install update from vendor's website.
References
- http://kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.33.1
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.17.9
- http://secunia.com/advisories/21563
- http://secunia.com/advisories/21695
- http://secunia.com/advisories/21847
- http://secunia.com/advisories/21934
- http://secunia.com/advisories/22093
- http://secunia.com/advisories/22148
- http://secunia.com/advisories/22292
- http://secunia.com/advisories/22945
- http://support.avaya.com/elmodocs2/security/ASA-2006-249.htm
- http://www.debian.org/security/2006/dsa-1184
- http://www.debian.org/security/2006/dsa-1237
- http://www.novell.com/linux/security/advisories/2006_21_sr.html
- http://www.novell.com/linux/security/advisories/2006_22_sr.html
- http://www.novell.com/linux/security/advisories/2006_57_kernel.html
- http://www.redhat.com/support/errata/RHSA-2006-0689.html
- http://www.securityfocus.com/bid/19615
- http://www.ubuntu.com/usn/usn-346-1
- http://www.vupen.com/english/advisories/2006/3330
- http://www.vupen.com/english/advisories/2006/3331
- https://issues.rpath.com/browse/RPL-611
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10666