Bug 85795 - Kernel: Potential ROSE and SCSI Tape vulns fixed in 2.6.12-rc1 (CVE-2005-3273)
|
Bug#:
85795
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: All
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: formula7@gentoo.org
|
|
Component: Kernel
|
|
|
URL:
http://secunia.com/advisories/14585/
|
|
Summary: Kernel: Potential ROSE and SCSI Tape vulns fixed in 2.6.12-rc1 (CVE-2005-3273)
|
|
Keywords:
|
|
Status Whiteboard: [linux < 2.6.12 ]
|
|
Opened: 2005-03-18 09:49 0000
|
Description:
Some vulnerabilities have been reported in the Linux kernel. One has an unknown impact, and the others can be exploited to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
1) An error exists in ROSE due to missing verification of the ndigis argument of new routes.
2) Any user with permissions to access a SCSI tape device can send some commands, which may cause it to become unusable for other users.
3) Some unspecified errors have been reported in the ISO9660 filesystem handler including Rock Ridge and Juliet extensions. These can be exploited via a specially crafted filesystem to cause a DoS or potentially corrupt memory leading to execution of arbitrary code.
Solution:
The vulnerabilities have been fixed in version 2.6.12-rc1.
Original Advisory:
Kernel.org:
http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.12-rc1
ISO9660 vulnerabilities are now treated in bug 86784
2) Any user with permissions to access a SCSI tape device can send some
commands, which may cause it to become unusable for other users.
Alan Cox says the patch to solve this is totally wrong, and I'd agree with my
basic knowledge of the SCSI command table. No proper fix is available (but I'm
not even sure if one is needed...)
ROSE Fixed in usermode-sources-2.6.11
All fixed in gentoo-sources-2.6.11-r7
tseng,tocharian,kang,trulux: you guys need these updates for
hardened-sources-2.6.x and rsbac-sources-2.6.x
Created an attachment (id=57762) [details]
The correct patch for the ROSE driver fix (wtihout the rest of cleanups and not
necessary changes)
This the right patch.
Thanks Tim for pointing out the right CSET.
rsbac-sources fixed with latest patch as r-s-2.6.11-r3
Removing Lorenzo from cc per request via email.