Skip to navigation

Security Advisory Updated 2.4 kernel available

Advisory: RHSA-2002:028-13
Type: Security Advisory
Severity: N/A
Issued on: 2002-02-13
Last updated on: 2002-02-27
Affected Products: Red Hat Linux 7.1
Red Hat Linux 7.2
CVEs (cve.mitre.org): CVE-2002-0060

Details

The Linux Netfilter team has found a problem in the "IRC connection
tracking" component of the firewall within the linux kernel. This problem
affects Red Hat Linux versions 7.1 and 7.2.

The Linux Netfilter team has found a problem in the IRC connection
tracking component of the firewall within the linux kernel. This component
is distributed with kernels in Red Hat Linux 7.1 and 7.2, although it is
not used in default installations.

The problem consists of an excessively broad netmask setting which is
applied to check if an "IRC DCC" connection through a masquerading firewall
should be allowed. This results in unwanted ports being opened on the
firewall, which could, depending on the firewall filter ruleset, allow
inbound connections.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2002-0060 to this issue. Thanks to Jozsef Kadlecsik
and Harald Welte of the netfilter team.

Users are advised to upgrade to this errata kernel containing patches
which fix these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied. Red Hat Linux 7.1 users should
update the packages in the XFree86 Erratum (RHEA-2002:010).

The procedure for upgrading the kernel is documented at:

http://www.redhat.com/support/docs/howto/kernel-upgrade/

Please read the directions for your architecture carefully before
proceeding with the kernel upgrade.

Please note that this update is also available via Red Hat Network. Many
people find this to be an easier way to apply updates. To use Red Hat
Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system. Note that you need to select the kernel
explicitly on default configurations of up2date.

Note for customers using Red Hat Linux for the IBM s/390:

Users of Red Hat Linux for the IBM s/390 with binary only kernel modules
(OCO) should contact their vendor to obtain updated modules for this kernel
patch.

Updated packages

Red Hat Linux 7.1

SRPMS:
kernel-2.4.9-31.src.rpm
File outdated by:  RHBA-2002:198
    MD5: 599a9027496067a54b46716c4af2184a
 
Alpha:
kernel-2.4.9-31.alpha.rpm
File outdated by:  RHSA-2002:205
    MD5: 4bccc363fdf0f00805ef4c34bbf8b43d
kernel-BOOT-2.4.9-31.alpha.rpm
File outdated by:  RHSA-2002:205
    MD5: 92f4dd670944fd607181089b04a1dcd9
kernel-doc-2.4.9-31.alpha.rpm
File outdated by:  RHSA-2002:205
    MD5: 5cb53f48285237d8027b17604ab39616
ftp://updates.redhat.com/rhn/repository/NULL/kernel-headers/2.4.9-31/alpha/kernel-headers-2.4.9-31.alpha.rpm
Missing file
    MD5: 9f95ed2c259c6eeb2cbc13a8e21a447c
kernel-smp-2.4.9-31.alpha.rpm
File outdated by:  RHSA-2002:205
    MD5: d43622963a55e817233a258d8318a120
kernel-source-2.4.9-31.alpha.rpm
File outdated by:  RHSA-2002:205
    MD5: 9d43960cc26be1783d8004addbb2bb9b
 
IA-32:
kernel-2.4.9-31.athlon.rpm
File outdated by:  RHSA-2003:417
    MD5: 8b0c9d11ee3f66790b4dca48f018e10b
kernel-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: 64705698f9f5eaf1e79185863382f941
kernel-2.4.9-31.i586.rpm
File outdated by:  RHSA-2003:417
    MD5: 8e50430f6c4f452d2625819ba7464c47
kernel-2.4.9-31.i686.rpm
File outdated by:  RHSA-2003:417
    MD5: 5e2b0b72141cbba077eb9c6b4d99991c
kernel-BOOT-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: b239ceebf5b5c28a348cd960d3195f03
kernel-debug-2.4.9-31.i686.rpm
File outdated by:  RHSA-2003:098
    MD5: a744dabe626acd95740aeb9af88b6d5b
kernel-doc-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: 6883d71ffe17dff75514ac38228cd5f0
kernel-enterprise-2.4.9-31.i686.rpm
File outdated by:  RHBA-2002:104
    MD5: aea058a30a30b3708b988c326ada6d0a
kernel-headers-2.4.9-31.i386.rpm
File outdated by:  RHBA-2002:104
    MD5: dae89931407ae5832e374e49d8347234
kernel-smp-2.4.9-31.athlon.rpm
File outdated by:  RHSA-2003:417
    MD5: 8e710a5f2a98932c2bc9e0d3d073e244
kernel-smp-2.4.9-31.i586.rpm
File outdated by:  RHSA-2003:417
    MD5: e72f4fd75463bba1d51b7c7df1999704
kernel-smp-2.4.9-31.i686.rpm
File outdated by:  RHSA-2003:417
    MD5: 3af0f1894a0c8b80486146298144727a
kernel-source-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: cba833ad4e2b45392e4de085ca0e920f
 
IA-64:
kernel-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2002:205
    MD5: 322164648ff900315ea8d062f43de2e8
kernel-doc-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2002:205
    MD5: 3f7c2c541be3797083cc7ac32e0fdebd
kernel-headers-2.4.9-31.ia64.rpm
File outdated by:  RHBA-2002:104
    MD5: c8681048d6817a289ca59e0b4c38e611
kernel-smp-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2002:205
    MD5: 19026b6d0ce77ce6ced75aa5de77b49a
kernel-source-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2002:205
    MD5: 2bdf102fd5b9e7b7e04c6e14d258eeae
 
Red Hat Linux 7.2

SRPMS:
kernel-2.4.9-31.src.rpm
File outdated by:  RHBA-2002:198
    MD5: 599a9027496067a54b46716c4af2184a
 
IA-32:
kernel-2.4.9-31.athlon.rpm
File outdated by:  RHSA-2003:417
    MD5: 8b0c9d11ee3f66790b4dca48f018e10b
kernel-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: 64705698f9f5eaf1e79185863382f941
kernel-2.4.9-31.i586.rpm
File outdated by:  RHSA-2003:417
    MD5: 8e50430f6c4f452d2625819ba7464c47
kernel-2.4.9-31.i686.rpm
File outdated by:  RHSA-2003:417
    MD5: 5e2b0b72141cbba077eb9c6b4d99991c
kernel-BOOT-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: b239ceebf5b5c28a348cd960d3195f03
kernel-debug-2.4.9-31.i686.rpm
File outdated by:  RHSA-2003:098
    MD5: a744dabe626acd95740aeb9af88b6d5b
kernel-doc-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: 6883d71ffe17dff75514ac38228cd5f0
kernel-enterprise-2.4.9-31.i686.rpm
File outdated by:  RHBA-2002:104
    MD5: aea058a30a30b3708b988c326ada6d0a
kernel-headers-2.4.9-31.i386.rpm
File outdated by:  RHBA-2002:104
    MD5: dae89931407ae5832e374e49d8347234
kernel-smp-2.4.9-31.athlon.rpm
File outdated by:  RHSA-2003:417
    MD5: 8e710a5f2a98932c2bc9e0d3d073e244
kernel-smp-2.4.9-31.i586.rpm
File outdated by:  RHSA-2003:417
    MD5: e72f4fd75463bba1d51b7c7df1999704
kernel-smp-2.4.9-31.i686.rpm
File outdated by:  RHSA-2003:417
    MD5: 3af0f1894a0c8b80486146298144727a
kernel-source-2.4.9-31.i386.rpm
File outdated by:  RHSA-2003:417
    MD5: cba833ad4e2b45392e4de085ca0e920f
 
IA-64:
kernel-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2003:098
    MD5: 322164648ff900315ea8d062f43de2e8
kernel-doc-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2003:098
    MD5: 3f7c2c541be3797083cc7ac32e0fdebd
kernel-headers-2.4.9-31.ia64.rpm
File outdated by:  RHBA-2002:104
    MD5: c8681048d6817a289ca59e0b4c38e611
kernel-smp-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2003:098
    MD5: 19026b6d0ce77ce6ced75aa5de77b49a
kernel-source-2.4.9-31.ia64.rpm
File outdated by:  RHSA-2003:098
    MD5: 2bdf102fd5b9e7b7e04c6e14d258eeae
 
s390:
kernel-2.4.9-31.s390.rpm
File outdated by:  RHBA-2002:198
    MD5: 03414b5deff2f6f673342ea3b8d5cf63
kernel-BOOT-2.4.9-31.s390.rpm
File outdated by:  RHBA-2002:198
    MD5: 29db2044bac2e46027afa7479f39a394
kernel-doc-2.4.9-31.s390.rpm
File outdated by:  RHBA-2002:198
    MD5: b24851e70837659048e8416e0552fb0f
kernel-headers-2.4.9-31.s390.rpm
File outdated by:  RHBA-2002:198
    MD5: b5ad515e3bffc79fdbc73a3e0b07b5cc
kernel-source-2.4.9-31.s390.rpm
File outdated by:  RHBA-2002:198
    MD5: 27d48439af20ab9f9b6ad84942913fe7
 

References


Keywords

connection, irc, lcall, netfilter, tracking


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/