Solution
Please Install the Updated Packages.
Insight
A vulnerability was discovered and corrected in the Linux 2.6 kernel:
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules
and (b) the gxsnmp package
does not properly validate length values
during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow
(2) an oid length of zero, which can lead to an
off-by-one error
or (3) an indefinite length for a primitive encoding.
To update your kernel, please follow the directions located at:
http://www.mandriva.com/en/security/kernelupdate
Affected
kernel on Mandriva Linux 2008.1,
Mandriva Linux 2008.1/X86_64
Severity
Classification
-
CVE CVE-2008-1673 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities