Summary
The remote host is missing an update to kernel
announced via advisory FEDORA-2009-8264.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kernel' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-8264
Insight
Update Information:
Update to linux kernel 2.6.27.29:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.26 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.27 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.28 http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.29
Fixes security bugs: CVE-2009-1895 CVE-2009-2406 CVE-2009-2407
ChangeLog:
* Fri Jul 31 2009 Chuck Ebbert 2.6.27.29-170.2.78 - The kernel package needs to override the new rpm %install behavior.
* Thu Jul 30 2009 Chuck Ebbert 2.6.27.29-170.2.77 - Linux 2.6.27.29
* Wed Jul 29 2009 Chuck Ebbert 2.6.27.29-170.2.75.rc1 - Linux 2.6.27.29-rc1 (CVE-2009-2406, CVE-2009-2407) - Drop linux-2.6-netdev-r8169-avoid-losing-msi-interrupts.patch, now in -stable.
* Wed Jul 29 2009 Chuck Ebbert 2.6.27.28-170.2.74 - Don't bounce virtio_blk requests (#510304)
* Mon Jul 27 2009 Chuck Ebbert 2.6.27.28-170.2.73 - Linux 2.6.27.28 (CVE-2009-1895, CVE-2009-1897)
Dropped patches, merged in stable:
linux-2.6-kbuild-fix-unifdef.c-usage-of-getline.patch linux-2.6-netdev-r8169-fix-lg-pkt-crash.patch
New config item:
CONFIG_DEFAULT_MMAP_MIN_ADDR=32768
References
Severity
Classification
-
CVE CVE-2008-5079, CVE-2009-0065, CVE-2009-1895, CVE-2009-1897, CVE-2009-2406, CVE-2009-2407 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities