[Ksplice][RHEL 4 Updates] New updates available via Ksplice (RHSA-2010:0718)
Tim Abbott
tabbott at ksplice.com
Wed Sep 29 15:58:10 PDT 2010
Synopsis: RHSA-2010:0718 can now be patched using Ksplice
CVEs: CVE-2010-3081
Red Hat Security Advisory Severity: Important
Systems running Red Hat Enterprise Linux 4 and CentOS 4 can now use
Ksplice to patch against the latest Red Hat Security Advisory,
RHSA-2010:0718.
INSTALLING THE UPDATES
We recommend that all Ksplice Uptrack RHEL 4 and CentOS 4 users install
these updates. You can install these updates by running:
# uptrack-upgrade -y
DESCRIPTION
* CVE-2010-3081: Privilege escalation through stack underflow in compat.
A flaw was found in the 32-bit compatibility layer for 64-bit systems.
User-space memory was allocated insecurely when translating system call
inputs to 64-bit. A stack pointer underflow could occur when using the
"compat_alloc_user_space" method with an arbitrary length input, as in
getsockopt.
SUPPORT
Ksplice support is available at support at ksplice.com or +1 765-577-5423.
More information about the RHEL4-Updates
mailing list