SB2007072101 - Configuration in Linux kernel
Published: July 21, 2007
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Configuration (CVE-ID: CVE-2007-3380)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the service.
Remediation
Install update from vendor's website.
References
- http://osvdb.org/37109
- http://secunia.com/advisories/26139
- http://secunia.com/advisories/27322
- http://www.redhat.com/support/errata/RHSA-2007-0940.html
- http://www.securityfocus.com/bid/24968
- http://www.ubuntu.com/usn/usn-489-1
- http://www.ubuntu.com/usn/usn-489-2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35516
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9337