Summary
The remote host is missing an update to linux-2.6
announced via advisory DSA 1862-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201862-1
Insight
A vulnerability has been discovered in the Linux kernel that may lead to privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problem:
CVE-2009-2692
Tavis Ormandy and Julien Tinnes discovered an issue with how the sendpage function is initialized in the proto_ops structure.
Local users can exploit this vulnerability to gain elevated privileges.
For the stable distribution (lenny), this problem has been fixed in version 2.6.26-17lenny2.
For the oldstable distribution (etch), this problem will be fixed in updates to linux-2.6 and linux-2.6.24.
We recommend that you upgrade your linux-2.6 and user-mode-linux
Severity
Classification
-
CVE CVE-2009-2692 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities