Summary
The remote host is missing updates announced in
advisory SUSE-SA:2009:051.
Solution
Update your system with the packages as indicated in the referenced security advisory.
https://secure1.securityspace.com/smysecure/catid.html?in=SUSE-SA:2009:051
Insight
The SUSE Linux Enterprise 11 and openSUSE 11.1 kernel was updated to 2.6.27.37 fixing various bugs and security issues.
Following security issues were fixed:
CVE-2009-2909: Unsigned check in the ax25 socket handler could allow local attackers to potentially crash the kernel or even execute code.
CVE-2009-3002: Fixed various socket handler getname leaks, which could disclose memory previously used by the kernel or other userland processes to the local attacker.
CVE-2009-2910: An information leakage with upper 32bit register values on x86_64 systems was fixed.
Various KVM stability and security fixes have also been added.
Severity
Classification
-
CVE CVE-2009-2909, CVE-2009-2910, CVE-2009-3002 -
CVSS Base Score: 4.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities