Summary
The remote host is missing an update to kernel
announced via advisory FEDORA-2009-9044.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kernel' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-9044
Insight
Update Information:
Security fixes:
- CVE-2009-2691: Information disclosure in proc filesystem - CVE-2009-2848: execve: must clear current->child_tid - CVE-2009-2849: md: null pointer dereference
- CVE-2009-2847: Information leak in do_sigaltstack
Restore missing LIRC drivers, dropped in previous release.
Backport upstream fixes that further improve the security of mmap of low addresses. (CVE-2009-2695)
ChangeLog:
* Thu Sep 24(??!!) 2009 Chuck Ebbert 2.6.29.6-217.2.16 - Fix CVE-2009-2691: local information disclosure in /proc * Fri Aug 21 2009 David Woodhouse
- Fix b43 on iMac G5 (#514787)
* Tue Aug 18 2009 Kyle McMartin
- CVE-2009-2848: execve: must clear current->clear_child_tid - Cherry pick upstream commits 52dec22e739eec8f3a0154f768a599f5489048bd which improve mmap_min_addr.
- CVE-2009-2849: md: avoid dereferencing null ptr when accessing suspend sysfs attributes.
- CVE-2009-2847: do_sigaltstack: avoid copying 'stack_t' as a structure to userspace
References
Severity
Classification
-
CVE CVE-2009-1895, CVE-2009-1897, CVE-2009-2406, CVE-2009-2407, CVE-2009-2691, CVE-2009-2692, CVE-2009-2695, CVE-2009-2767, CVE-2009-2847, CVE-2009-2848, CVE-2009-2849 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities