-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 -------------------------------------------------------------------------- Turbolinux Security Advisory TLSA-2004-7 http://www.turbolinux.co.jp/security/ security-team@turbolinux.co.jp -------------------------------------------------------------------------- Original released date : 23 Feb 2004 Last revised : 23 Feb 2004 Package : kernel Summary : kernel mremap vulnerability More information : The kernel package contains the Linux kernel (vmlinuz), the core of your Linux operating system. The kernel handles the basic functions of the operating system. The Linux memory management subsystem (mremap) isssue have been discovered in Kernel2.4. This vulnerability is a different than TLSA-2004-1. Impact : The local users may be able to gain root privileges. Affected Products : - Turbolinux 8 Server - Turbolinux 8 Workstation - Turbolinux 7 Server - Turbolinux 7 Workstation Solution : Please use turbopkg(zabom) tool to apply the update. --------------------------------------------- # turbopkg or # zabom update kernel kernel-BOOT kernel-doc kernel-headers kernel-pcmcia-cs \ kernel-smp kernel-smp64G kernel-source --------------------------------------------- Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/SRPMS/kernel-2.4.18-17.src.rpm 41913933 5ccb9a89c3be94deab1c97ab586c09c9 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-2.4.18-17.i586.rpm 14075980 30ccd11d880a7e0e32bbee21439ec709 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-BOOT-2.4.18-17.i586.rpm 7101289 e30110e267be513da3c358ad0d4b4550 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-doc-2.4.18-17.i586.rpm 1457830 24714114e93a4a93a814cdf4498159bc ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-headers-2.4.18-17.i586.rpm 1816441 85f24c7dd6dd7cf8da00e8050c124195 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-pcmcia-cs-2.4.18-17.i586.rpm 329393 488edeb522ce0790bf4298e8d11b25eb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-smp-2.4.18-17.i586.rpm 14549351 a17c70329b0912939a60bb4ca9017049 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-smp64G-2.4.18-17.i586.rpm 14542476 c5346adab1623182b4c75e6392a08d62 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-source-2.4.18-17.i586.rpm 26544848 6fe1468ae10699ea55b0421c8e89db32 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/SRPMS/kernel-2.4.18-17.src.rpm 41913933 5ccb9a89c3be94deab1c97ab586c09c9 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-2.4.18-17.i586.rpm 14075980 30ccd11d880a7e0e32bbee21439ec709 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-BOOT-2.4.18-17.i586.rpm 7101289 e30110e267be513da3c358ad0d4b4550 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-doc-2.4.18-17.i586.rpm 1457830 24714114e93a4a93a814cdf4498159bc ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-headers-2.4.18-17.i586.rpm 1816441 85f24c7dd6dd7cf8da00e8050c124195 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-pcmcia-cs-2.4.18-17.i586.rpm 329393 488edeb522ce0790bf4298e8d11b25eb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-smp-2.4.18-17.i586.rpm 14549351 a17c70329b0912939a60bb4ca9017049 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-smp64G-2.4.18-17.i586.rpm 14542476 c5346adab1623182b4c75e6392a08d62 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-source-2.4.18-17.i586.rpm 26544848 6fe1468ae10699ea55b0421c8e89db32 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/SRPMS/kernel-2.4.18-17.src.rpm 41913933 5ccb9a89c3be94deab1c97ab586c09c9 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-2.4.18-17.i586.rpm 14075980 30ccd11d880a7e0e32bbee21439ec709 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-BOOT-2.4.18-17.i586.rpm 7101289 e30110e267be513da3c358ad0d4b4550 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-doc-2.4.18-17.i586.rpm 1457830 24714114e93a4a93a814cdf4498159bc ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-headers-2.4.18-17.i586.rpm 1816441 85f24c7dd6dd7cf8da00e8050c124195 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-pcmcia-cs-2.4.18-17.i586.rpm 329393 488edeb522ce0790bf4298e8d11b25eb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-smp-2.4.18-17.i586.rpm 14549351 a17c70329b0912939a60bb4ca9017049 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-smp64G-2.4.18-17.i586.rpm 14542476 c5346adab1623182b4c75e6392a08d62 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-source-2.4.18-17.i586.rpm 26544848 6fe1468ae10699ea55b0421c8e89db32 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/SRPMS/kernel-2.4.18-17.src.rpm 41913933 5ccb9a89c3be94deab1c97ab586c09c9 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-2.4.18-17.i586.rpm 14075980 30ccd11d880a7e0e32bbee21439ec709 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-BOOT-2.4.18-17.i586.rpm 7101289 e30110e267be513da3c358ad0d4b4550 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-doc-2.4.18-17.i586.rpm 1457830 24714114e93a4a93a814cdf4498159bc ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-headers-2.4.18-17.i586.rpm 1816441 85f24c7dd6dd7cf8da00e8050c124195 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-pcmcia-cs-2.4.18-17.i586.rpm 329393 488edeb522ce0790bf4298e8d11b25eb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-smp-2.4.18-17.i586.rpm 14549351 a17c70329b0912939a60bb4ca9017049 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-smp64G-2.4.18-17.i586.rpm 14542476 c5346adab1623182b4c75e6392a08d62 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-source-2.4.18-17.i586.rpm 26544848 6fe1468ae10699ea55b0421c8e89db32 References : CVE [CAN-2004-0077] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0077 -------------------------------------------------------------------------- Revision History 23 Feb 2004 Initial release -------------------------------------------------------------------------- Copyright(C) 2004 Turbolinux, Inc. All rights reserved. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQFAOZB5K0LzjOqIJMwRAnSeAJ4/uJg0ss5Hcy3N28bISMa7rfyFVQCcDfhA VcspK6GK0B1i3VF9qB3SNRo= =AWzE -----END PGP SIGNATURE-----