|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2010-4

Novell eDirectory eMBox SOAP Request Denial of Service Vulnerability

Original Issue Date: February 18, 2010

Severity Rating: Low

Systems Affected

  • Linux Kernel versions prior to 2.6.33-rc7

Overview

A vulnerability has been reported in Linux Kernel, which could be exploited by local attackers to gain knowledge of sensitive information or cause a denial of service(DoS) condition.

Description

This vulnerability is caused by an error in the "do_pages_move()" [mm/migrate.c] function failing to explicitly test node values read from user-space. An attacker could exploit this vulnerability by using a large value or a negative value , to obtain sensitive information or to panic a vulnerable system, resulting in a denial of service (DoS) condition.

Solution

Upgrade to version 2.6.33-rc7 :
http://www.kernel.org/

Vendor Information

kernel.org
http://www.kernel.org/

References

kernel.org
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.33-rc7

Secunia
http://secunia.com/advisories/38502/

VUPEN Security
http://www.vupen.com/english/advisories/2010/0329

SecurityTracker
http://securitytracker.com/alerts/2010/Feb/1023554.html

CVE Name
CVE-2010-0415

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 
10-Jul-2011ext/css">

Last Updated 09-Jul-2009
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +