lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <200406181746.19246.security-announce@turbolinux.co.jp>
From: security-announce at turbolinux.co.jp (Turbolinux)
Subject: [TURBOLINUX SECURITY INFO] 18/Jun/2004

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

This is an announcement only email list for the x86 architecture.
============================================================
Turbolinux Security Announcement 18/Jun/2004
============================================================

The following page contains the security information of Turbolinux Inc.

 - Turbolinux Security Center
   http://www.turbolinux.com/security/

 (1) kernel -> kernel crash

===========================================================
* kernel -> kernel crash
===========================================================

 More information :
    The kernel package contains the Linux kernel (vmlinuz), the core of your Linux operating system.
    Linux kernel 2.4.2x and 2.6.x for x86 allows local users to cause a denial of service (system crash),
    possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave
    and frstor instructions, as originally demonstrated using a "crash.c" program.

 Impact :
    The vulnerability allows an attacker to make the cause of the denial of service of the kernel.

 Affected Products :
    - Turbolinux Appliance Server 1.0 Hosting Edition
    - Turbolinux Appliance Server 1.0 Workgroup Edition
    - Turbolinux 10 F...
    - Turbolinux 10 Desktop
    - Turbolinux 8 Server
    - Turbolinux 8 Workstation
    - Turbolinux 7 Server
    - Turbolinux 7 Workstation

 Solution :
    Please use the turbopkg (zabom) tool to apply the update. 
 ---------------------------------------------
 [Turbolinux 10 Desktop, Turbolinux 10 F...]
 # zabom -u kernel kernel-doc kernel-extramodules kernel-headers kernel-pcmcia-cs \
            kernel-smp kernel-source

 [other]
 # turbopkg
 or
 # zabom update kernel kernel-BOOT kernel-doc kernel-headers \
                kernel-pcmcia-cs kernel-smp kernel-smp64G kernel-source
 ---------------------------------------------


 <Turbolinux Appliance Server 1.0 Hosting Edition>

   Source Packages
   Size : MD5

   kernel-2.4.25-4.src.rpm
     36883928 1a0c7251fbbe08cca0cf675661c7c92e

   Binary Packages
   Size : MD5

   kernel-2.4.25-4.i586.rpm
     13778668 b2c70992005e4ccbd977f8a7e5675a2b
   kernel-BOOT-2.4.25-4.i586.rpm
      6893062 184da8748cbf34bf02f4c2447cd884ed
   kernel-doc-2.4.25-4.i586.rpm
      1573535 3ad161e9b63fe5bb74a48a8314ec6036
   kernel-headers-2.4.25-4.i586.rpm
      1985516 4f86ac6c5886303f372f0c40d9905397
   kernel-pcmcia-cs-2.4.25-4.i586.rpm
       365947 a0ae1fdcaa42cabe3241fda906060602
   kernel-smp-2.4.25-4.i586.rpm
     14175739 89bebc7ab668bc85610aa99bc1d3e280
   kernel-smp64G-2.4.25-4.i586.rpm
     14153765 3877f89cc0eaa9f50b7975485e727ba7
   kernel-source-2.4.25-4.i586.rpm
     27486092 214ad563f4b90eb1042925cea94ab1c3

 <Turbolinux Appliance Server 1.0 Workgroup Edition>

   Source Packages
   Size : MD5

   kernel-2.4.25-4.src.rpm
     36883928 b868b87c5d68c23f33b63be09d04927c

   Binary Packages
   Size : MD5

   kernel-2.4.25-4.i586.rpm
     13778668 a20391455654c4c926b82fec0402627c
   kernel-BOOT-2.4.25-4.i586.rpm
      6893062 09bd9dd0c8d58838c943ba6d02df5f8a
   kernel-doc-2.4.25-4.i586.rpm
      1573535 a30f53f38e9cd4ee68502bd6ad9feb10
   kernel-headers-2.4.25-4.i586.rpm
      1985516 75a2ec75a7f9802a45f3a6dd0eb3ddb5
   kernel-pcmcia-cs-2.4.25-4.i586.rpm
       365947 e9e12baeb409c11de972c11d92913ba2
   kernel-smp-2.4.25-4.i586.rpm
     14175739 9acd15559159dcc36f6f20c291f5347d
   kernel-smp64G-2.4.25-4.i586.rpm
     14153765 a191020097cf3dd49c0e07a1b975a3b4
   kernel-source-2.4.25-4.i586.rpm
     27486092 08fe3278215645e673eb7b38d3088cc5

 <Turbolinux 10 Desktop, Turbolinux 10 F...>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/SRPMS/kernel-2.6.0-10.src.rpm
     47398657 8425b46a3c0bd5bee48302db26428790

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-2.6.0-10.i586.rpm
     13232411 669d134e9c520ca9ec339975cd1145ec
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-doc-2.6.0-10.i586.rpm
      1662236 e5a991e66635db340b3630970c4a6ced
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-extramodules-2.6.0-10.i586.rpm
      2965707 171a5942be6a1520a8612dc6477abecd
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-headers-2.6.0-10.i586.rpm
      1754211 e1ff3f3d6c32d5dbae532a835c62c429
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-pcmcia-cs-2.6.0-10.i586.rpm
       316045 a2cc2701e27605f005a53bd5c26ba3f9
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-smp-2.6.0-10.i586.rpm
     13691573 7e3a2fc3cbfae5b2c2500bb5428707cc
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-source-2.6.0-10.i586.rpm
     28533683 98d8843842ffb57c318d730c7f372bd3

 <Turbolinux 8 Server>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/SRPMS/kernel-2.4.18-20.src.rpm
     42490471 2474d13e42a4d5428e0364013a3e85b2

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-2.4.18-20.i586.rpm
     14113582 f598c4484cdd94ba1111d6f16ebfaac6
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm
      7155416 2fe7f368c0eb45660f83644b66c7c088
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm
      1459279 4577dde9901c9a7c7189968aa833ad81
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm
      1823816 b799c758422e19a3773e111658e72608
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm
       331484 011b0aac10fe484534ef83bd837f4445
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm
     14622987 00bfb603f11f78a80f0a590f2b9107bb
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm
     14608429 193d6331f4efac846923176dba979545
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-source-2.4.18-20.i586.rpm
     26626970 b86cde45808ffa1d92e0b1886a54dba9

 <Turbolinux 8 Workstation>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/SRPMS/kernel-2.4.18-20.src.rpm
     42490471 2474d13e42a4d5428e0364013a3e85b2

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-2.4.18-20.i586.rpm
     14113582 f598c4484cdd94ba1111d6f16ebfaac6
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm
      7155416 2fe7f368c0eb45660f83644b66c7c088
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm
      1459279 4577dde9901c9a7c7189968aa833ad81
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm
      1823816 b799c758422e19a3773e111658e72608
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm
       331484 011b0aac10fe484534ef83bd837f4445
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm
     14622987 00bfb603f11f78a80f0a590f2b9107bb
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm
     14608429 193d6331f4efac846923176dba979545
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-source-2.4.18-20.i586.rpm
     26626970 b86cde45808ffa1d92e0b1886a54dba9

 <Turbolinux 7 Server>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/SRPMS/kernel-2.4.18-20.src.rpm
     42490471 2474d13e42a4d5428e0364013a3e85b2

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-2.4.18-20.i586.rpm
     14113582 f598c4484cdd94ba1111d6f16ebfaac6
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm
      7155416 2fe7f368c0eb45660f83644b66c7c088
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm
      1459279 4577dde9901c9a7c7189968aa833ad81
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm
      1823816 b799c758422e19a3773e111658e72608
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm
       331484 011b0aac10fe484534ef83bd837f4445
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm
     14622987 00bfb603f11f78a80f0a590f2b9107bb
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm
     14608429 193d6331f4efac846923176dba979545
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-source-2.4.18-20.i586.rpm
     26626970 b86cde45808ffa1d92e0b1886a54dba9

 <Turbolinux 7 Workstation>

   Source Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/SRPMS/kernel-2.4.18-20.src.rpm
     42490471 2474d13e42a4d5428e0364013a3e85b2

   Binary Packages
   Size : MD5

   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-2.4.18-20.i586.rpm
     14113582 f598c4484cdd94ba1111d6f16ebfaac6
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm
      7155416 2fe7f368c0eb45660f83644b66c7c088
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm
      1459279 4577dde9901c9a7c7189968aa833ad81
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm
      1823816 b799c758422e19a3773e111658e72608
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm
       331484 011b0aac10fe484534ef83bd837f4445
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm
     14622987 00bfb603f11f78a80f0a590f2b9107bb
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm
     14608429 193d6331f4efac846923176dba979545
   ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-source-2.4.18-20.i586.rpm
     26626970 b86cde45808ffa1d92e0b1886a54dba9


 References:

 CVE
   [CAN-2004-0554]
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0554


 * You may need to update the turbopkg tool before applying the update.
Please refer to the following URL for detailed information.

  http://www.turbolinux.com/download/zabom.html
  http://www.turbolinux.com/download/zabomupdate.html

Package Update Path
http://www.turbolinux.com/update

============================================================
 * To obtain the public key

Here is the public key

 http://www.turbolinux.com/security/

 * To unsubscribe from the list

If you ever want to remove yourself from this mailing list,
  you can send a message to <server-users-e-ctl@...bolinux.co.jp> with
the word `unsubscribe' in the body (don't include the quotes).

unsubscribe

 * To change your email address

If you ever want to chage email address in this mailing list,
  you can send a message to <server-users-e-ctl@...bolinux.co.jp> with
the following command in the message body:

  chaddr 'old address' 'new address'

If you have any questions or problems, please contact
<supp_info@...bolinux.co.jp>

Thank you!

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFA0qvUK0LzjOqIJMwRAgKIAKCjZuJThyXzCwHqL4WSzQJwoRQgPwCgtwiM
3j7OWZdMqoVZfaoN5E2hunA=
=JjuT
-----END PGP SIGNATURE-----




Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ