[Security Announce] [ MDKSA-2006:087 ] - Updated kernel packages fixes netfilter SNMP NAT memory corruption
Posted on: 05/24/2006 06:52 PM

The Mandriva Security Team published a new security update for Mandriva Linux. Here the announcement:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDKSA-2006:087
http://www.mandriva.com/security/
_______________________________________________________________________

Package : kernel
Date : May 24, 2006
Affected: 2006.0
_______________________________________________________________________

Problem Description:

Memory corruption can be triggered remotely when the ip_nat_snmp_basic
module is loaded and traffic on port 161 or 162 is NATed.

The provided packages are patched to fix this vulnerability. Users
who may be running netfilter on important servers are encouraged to
upgrade to these updated kernels.

To update your kernel, please follow the directions located at:

http://www.mandriva.com/en/security/kernelupdate
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2444
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2006.0:
4dc3aebce01743d22ccfdcf2d7e6be1c 2006.0/RPMS/kernel-2.6.12.22mdk-1-1mdk.i586.rpm
4df75974100f1d867b227f83aac9bc2e 2006.0/RPMS/kernel-BOOT-2.6.12.22mdk-1-1mdk.i586.rpm
7ad9ef00021f9e0938932014f22e4bba 2006.0/RPMS/kernel-i586-up-1GB-2.6.12.22mdk-1-1mdk.i586.rpm
44eae16e32239f239346e620cd0f7b15 2006.0/RPMS/kernel-i686-up-4GB-2.6.12.22mdk-1-1mdk.i586.rpm
e01abef21d8d14e6d6c879f56ebe684b 2006.0/RPMS/kernel-smp-2.6.12.22mdk-1-1mdk.i586.rpm
5d3826385c72a86a3ebcf564529d85b1 2006.0/RPMS/kernel-source-2.6-2.6.12-22mdk.i586.rpm
79586cea137b4d36658d3fd7b313ef8b 2006.0/RPMS/kernel-source-stripped-2.6-2.6.12-22mdk.i586.rpm
883243ea22ad7eb494b1546a4a390507 2006.0/RPMS/kernel-xbox-2.6.12.22mdk-1-1mdk.i586.rpm
4283b2f1fefe78b8459ffb3611fb1273 2006.0/RPMS/kernel-xen0-2.6.12.22mdk-1-1mdk.i586.rpm
eb25ea2db1336906f145cf20a84f29a6 2006.0/RPMS/kernel-xenU-2.6.12.22mdk-1-1mdk.i586.rpm
f34885d9d75928e9371f1ca3dd620fd3 2006.0/SRPMS/kernel-2.6.12.22mdk-1-1mdk.src.rpm

Mandriva Linux 2006.0/X86_64:
94fc9062208f2bc8010f64070f505133 x86_64/2006.0/RPMS/kernel-2.6.12.22mdk-1-1mdk.x86_64.rpm
fad1ee518ba360420a9dc7f544ace3ee x86_64/2006.0/RPMS/kernel-BOOT-2.6.12.22mdk-1-1mdk.x86_64.rpm
88d61abf3296793a136cc8c662030b34 x86_64/2006.0/RPMS/kernel-smp-2.6.12.22mdk-1-1mdk.x86_64.rpm
d57c2d28a28e66b2eafe716d22971619 x86_64/2006.0/RPMS/kernel-source-2.6-2.6.12-22mdk.x86_64.rpm
6c0ff6667a79390e8260d30ff7f2faa5 x86_64/2006.0/RPMS/kernel-source-stripped-2.6-2.6.12-22mdk.x86_64.rpm
f34885d9d75928e9371f1ca3dd620fd3 x86_64/2006.0/SRPMS/kernel-2.6.12.22mdk-1-1mdk.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
lt;security*mandriva.comgt;
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFEdG6amqjQ0CJFipgRAlIZAJ9VNo3owfm29R6Bwwz/hEb3Fnj1+gCgoLvU
Xgr8zIydmU2uUC1TH2wbbCo=
=yoXm
-----END PGP SIGNATURE-----



Printed from Linux Compatible (http://www.linuxcompatible.org/news/story/security_announce_mdksa_2006087__updated_kernel_packages_fixes_netfilter_snmp_nat_memory_corruption.html)