Skip to navigation

Security Advisory kernel security update

Advisory: RHSA-2004:354-08
Type: Security Advisory
Severity: Moderate
Issued on: 2004-07-02
Last updated on: 2004-07-02
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
CVEs (cve.mitre.org): CVE-2004-0497

Details

Updated kernel packages that fix a security vulnerability affecting the
kernel nfs server for Red Hat Enterprise Linux 2.1 are now available.

The Linux kernel handles the basic functions of the operating system.

During an audit of the Linux kernel, SUSE discovered a flaw that allowed
a user to make unauthorized changes to the group ID of files in certain
circumstances. In the 2.4 kernel, as shipped with Red Hat Enterprise
Linux, the only way this could happen is through the kernel nfs server. A
user on a system that mounted a remote file system from a vulnerable
machine may be able to make unauthorized changes to the group ID of
exported files. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0497 to this issue.

Only Red Hat Enterprise Linux systems that are configured to share file
systems via NFS are affected by this issue.

All Red Hat Enterprise Linux 2.1 users are advised to upgrade their kernels
to the packages associated with their machine architectures and
configurations as listed in this erratum. These packages contain a
backported patch to correct this issue.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

If up2date fails to connect to Red Hat Network due to SSL
Certificate Errors, you need to install a version of the
up2date client with an updated certificate. The latest version of
up2date is available from the Red Hat FTP site and may also be
downloaded directly from the RHN website:

https://rhn.redhat.com/help/latest-up2date.pxt

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
kernel-2.4.9-e.43.src.rpm
File outdated by:  RHSA-2009:0001
    MD5: bad14d2ab6a12b23b3aa9ef8b5563f90
 
IA-32:
kernel-2.4.9-e.43.athlon.rpm
File outdated by:  RHSA-2009:0001
    MD5: ec22fbd91073d3e4ef676935a16a4583
kernel-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 2c2ff05ad0fdd66e821bd05ffb9f956f
kernel-BOOT-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 9f01e5471be6100b787151a1fea85dc5
kernel-debug-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 1d6847158ce5c9ddb3b94f8d1eb78358
kernel-doc-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 123517b827d3a1e534a562351e626836
kernel-enterprise-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: e58a717e3ee9704cbfb46209bc2a8e9e
kernel-headers-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: d1afa3ed4a95146cdde561808118f9ba
kernel-smp-2.4.9-e.43.athlon.rpm
File outdated by:  RHSA-2009:0001
    MD5: eb5fc9756bf70c3dff35686e387edb48
kernel-smp-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: ee8735747a63f55e9cb718e0e5bf0043
kernel-source-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 73a26f9b34e8777a0df60526fa0de398
kernel-summit-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 3e77c90ec0249d12ead10628e7ac203c
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
kernel-2.4.9-e.43.src.rpm
File outdated by:  RHSA-2009:0001
    MD5: bad14d2ab6a12b23b3aa9ef8b5563f90
 
IA-32:
kernel-2.4.9-e.43.athlon.rpm
File outdated by:  RHSA-2009:0001
    MD5: ec22fbd91073d3e4ef676935a16a4583
kernel-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 2c2ff05ad0fdd66e821bd05ffb9f956f
kernel-BOOT-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 9f01e5471be6100b787151a1fea85dc5
kernel-debug-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 1d6847158ce5c9ddb3b94f8d1eb78358
kernel-doc-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 123517b827d3a1e534a562351e626836
kernel-headers-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: d1afa3ed4a95146cdde561808118f9ba
kernel-smp-2.4.9-e.43.athlon.rpm
File outdated by:  RHSA-2009:0001
    MD5: eb5fc9756bf70c3dff35686e387edb48
kernel-smp-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: ee8735747a63f55e9cb718e0e5bf0043
kernel-source-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 73a26f9b34e8777a0df60526fa0de398
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
kernel-2.4.9-e.43.src.rpm
File outdated by:  RHSA-2009:0001
    MD5: bad14d2ab6a12b23b3aa9ef8b5563f90
 
IA-32:
kernel-2.4.9-e.43.athlon.rpm
File outdated by:  RHSA-2009:0001
    MD5: ec22fbd91073d3e4ef676935a16a4583
kernel-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 2c2ff05ad0fdd66e821bd05ffb9f956f
kernel-BOOT-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 9f01e5471be6100b787151a1fea85dc5
kernel-debug-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: 1d6847158ce5c9ddb3b94f8d1eb78358
kernel-doc-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 123517b827d3a1e534a562351e626836
kernel-enterprise-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: e58a717e3ee9704cbfb46209bc2a8e9e
kernel-headers-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: d1afa3ed4a95146cdde561808118f9ba
kernel-smp-2.4.9-e.43.athlon.rpm
File outdated by:  RHSA-2009:0001
    MD5: eb5fc9756bf70c3dff35686e387edb48
kernel-smp-2.4.9-e.43.i686.rpm
File outdated by:  RHSA-2009:0001
    MD5: ee8735747a63f55e9cb718e0e5bf0043
kernel-source-2.4.9-e.43.i386.rpm
File outdated by:  RHSA-2009:0001
    MD5: 73a26f9b34e8777a0df60526fa0de398
 

References


Keywords

inode_change_ok, knfsd


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/