From security-announce@turbolinux.co.jp Fri Jun 18 11:32:48 2004 From: Turbolinux Resent-From: security-announce@turbolinux.co.jp To: security-announce@turbolinux.co.jp Resent-To: server-users-e@turbolinux.co.jp (moderated) Date: Fri, 18 Jun 2004 17:46:08 +0900 Reply-To: server-users-e@turbolinux.co.jp Subject: [Full-Disclosure] [TURBOLINUX SECURITY INFO] 18/Jun/2004 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is an announcement only email list for the x86 architecture. ============================================================ Turbolinux Security Announcement 18/Jun/2004 ============================================================ The following page contains the security information of Turbolinux Inc. - Turbolinux Security Center http://www.turbolinux.com/security/ (1) kernel -> kernel crash =========================================================== * kernel -> kernel crash =========================================================== More information : The kernel package contains the Linux kernel (vmlinuz), the core of your Linux operating system. Linux kernel 2.4.2x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program. Impact : The vulnerability allows an attacker to make the cause of the denial of service of the kernel. Affected Products : - Turbolinux Appliance Server 1.0 Hosting Edition - Turbolinux Appliance Server 1.0 Workgroup Edition - Turbolinux 10 F... - Turbolinux 10 Desktop - Turbolinux 8 Server - Turbolinux 8 Workstation - Turbolinux 7 Server - Turbolinux 7 Workstation Solution : Please use the turbopkg (zabom) tool to apply the update. --------------------------------------------- [Turbolinux 10 Desktop, Turbolinux 10 F...] # zabom -u kernel kernel-doc kernel-extramodules kernel-headers kernel-pcmcia-cs \ kernel-smp kernel-source [other] # turbopkg or # zabom update kernel kernel-BOOT kernel-doc kernel-headers \ kernel-pcmcia-cs kernel-smp kernel-smp64G kernel-source --------------------------------------------- Source Packages Size : MD5 kernel-2.4.25-4.src.rpm 36883928 1a0c7251fbbe08cca0cf675661c7c92e Binary Packages Size : MD5 kernel-2.4.25-4.i586.rpm 13778668 b2c70992005e4ccbd977f8a7e5675a2b kernel-BOOT-2.4.25-4.i586.rpm 6893062 184da8748cbf34bf02f4c2447cd884ed kernel-doc-2.4.25-4.i586.rpm 1573535 3ad161e9b63fe5bb74a48a8314ec6036 kernel-headers-2.4.25-4.i586.rpm 1985516 4f86ac6c5886303f372f0c40d9905397 kernel-pcmcia-cs-2.4.25-4.i586.rpm 365947 a0ae1fdcaa42cabe3241fda906060602 kernel-smp-2.4.25-4.i586.rpm 14175739 89bebc7ab668bc85610aa99bc1d3e280 kernel-smp64G-2.4.25-4.i586.rpm 14153765 3877f89cc0eaa9f50b7975485e727ba7 kernel-source-2.4.25-4.i586.rpm 27486092 214ad563f4b90eb1042925cea94ab1c3 Source Packages Size : MD5 kernel-2.4.25-4.src.rpm 36883928 b868b87c5d68c23f33b63be09d04927c Binary Packages Size : MD5 kernel-2.4.25-4.i586.rpm 13778668 a20391455654c4c926b82fec0402627c kernel-BOOT-2.4.25-4.i586.rpm 6893062 09bd9dd0c8d58838c943ba6d02df5f8a kernel-doc-2.4.25-4.i586.rpm 1573535 a30f53f38e9cd4ee68502bd6ad9feb10 kernel-headers-2.4.25-4.i586.rpm 1985516 75a2ec75a7f9802a45f3a6dd0eb3ddb5 kernel-pcmcia-cs-2.4.25-4.i586.rpm 365947 e9e12baeb409c11de972c11d92913ba2 kernel-smp-2.4.25-4.i586.rpm 14175739 9acd15559159dcc36f6f20c291f5347d kernel-smp64G-2.4.25-4.i586.rpm 14153765 a191020097cf3dd49c0e07a1b975a3b4 kernel-source-2.4.25-4.i586.rpm 27486092 08fe3278215645e673eb7b38d3088cc5 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/SRPMS/kernel-2.6.0-10.src.rpm 47398657 8425b46a3c0bd5bee48302db26428790 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-2.6.0-10.i586.rpm 13232411 669d134e9c520ca9ec339975cd1145ec ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-doc-2.6.0-10.i586.rpm 1662236 e5a991e66635db340b3630970c4a6ced ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-extramodules-2.6.0-10.i586.rpm 2965707 171a5942be6a1520a8612dc6477abecd ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-headers-2.6.0-10.i586.rpm 1754211 e1ff3f3d6c32d5dbae532a835c62c429 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-pcmcia-cs-2.6.0-10.i586.rpm 316045 a2cc2701e27605f005a53bd5c26ba3f9 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-smp-2.6.0-10.i586.rpm 13691573 7e3a2fc3cbfae5b2c2500bb5428707cc ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/updates/RPMS/kernel-source-2.6.0-10.i586.rpm 28533683 98d8843842ffb57c318d730c7f372bd3 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/SRPMS/kernel-2.4.18-20.src.rpm 42490471 2474d13e42a4d5428e0364013a3e85b2 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-2.4.18-20.i586.rpm 14113582 f598c4484cdd94ba1111d6f16ebfaac6 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm 7155416 2fe7f368c0eb45660f83644b66c7c088 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm 1459279 4577dde9901c9a7c7189968aa833ad81 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm 1823816 b799c758422e19a3773e111658e72608 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm 331484 011b0aac10fe484534ef83bd837f4445 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm 14622987 00bfb603f11f78a80f0a590f2b9107bb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm 14608429 193d6331f4efac846923176dba979545 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updates/RPMS/kernel-source-2.4.18-20.i586.rpm 26626970 b86cde45808ffa1d92e0b1886a54dba9 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/SRPMS/kernel-2.4.18-20.src.rpm 42490471 2474d13e42a4d5428e0364013a3e85b2 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-2.4.18-20.i586.rpm 14113582 f598c4484cdd94ba1111d6f16ebfaac6 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm 7155416 2fe7f368c0eb45660f83644b66c7c088 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm 1459279 4577dde9901c9a7c7189968aa833ad81 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm 1823816 b799c758422e19a3773e111658e72608 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm 331484 011b0aac10fe484534ef83bd837f4445 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm 14622987 00bfb603f11f78a80f0a590f2b9107bb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm 14608429 193d6331f4efac846923176dba979545 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/updates/RPMS/kernel-source-2.4.18-20.i586.rpm 26626970 b86cde45808ffa1d92e0b1886a54dba9 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/SRPMS/kernel-2.4.18-20.src.rpm 42490471 2474d13e42a4d5428e0364013a3e85b2 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-2.4.18-20.i586.rpm 14113582 f598c4484cdd94ba1111d6f16ebfaac6 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm 7155416 2fe7f368c0eb45660f83644b66c7c088 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm 1459279 4577dde9901c9a7c7189968aa833ad81 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm 1823816 b799c758422e19a3773e111658e72608 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm 331484 011b0aac10fe484534ef83bd837f4445 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm 14622987 00bfb603f11f78a80f0a590f2b9107bb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm 14608429 193d6331f4efac846923176dba979545 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updates/RPMS/kernel-source-2.4.18-20.i586.rpm 26626970 b86cde45808ffa1d92e0b1886a54dba9 Source Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/SRPMS/kernel-2.4.18-20.src.rpm 42490471 2474d13e42a4d5428e0364013a3e85b2 Binary Packages Size : MD5 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-2.4.18-20.i586.rpm 14113582 f598c4484cdd94ba1111d6f16ebfaac6 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-BOOT-2.4.18-20.i586.rpm 7155416 2fe7f368c0eb45660f83644b66c7c088 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-doc-2.4.18-20.i586.rpm 1459279 4577dde9901c9a7c7189968aa833ad81 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-headers-2.4.18-20.i586.rpm 1823816 b799c758422e19a3773e111658e72608 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-pcmcia-cs-2.4.18-20.i586.rpm 331484 011b0aac10fe484534ef83bd837f4445 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-smp-2.4.18-20.i586.rpm 14622987 00bfb603f11f78a80f0a590f2b9107bb ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-smp64G-2.4.18-20.i586.rpm 14608429 193d6331f4efac846923176dba979545 ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/updates/RPMS/kernel-source-2.4.18-20.i586.rpm 26626970 b86cde45808ffa1d92e0b1886a54dba9 References: CVE [CAN-2004-0554] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0554 * You may need to update the turbopkg tool before applying the update. Please refer to the following URL for detailed information. http://www.turbolinux.com/download/zabom.html http://www.turbolinux.com/download/zabomupdate.html Package Update Path http://www.turbolinux.com/update ============================================================ * To obtain the public key Here is the public key http://www.turbolinux.com/security/ * To unsubscribe from the list If you ever want to remove yourself from this mailing list, you can send a message to with the word `unsubscribe' in the body (don't include the quotes). unsubscribe * To change your email address If you ever want to chage email address in this mailing list, you can send a message to with the following command in the message body: chaddr 'old address' 'new address' If you have any questions or problems, please contact Thank you! -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFA0qvUK0LzjOqIJMwRAgKIAKCjZuJThyXzCwHqL4WSzQJwoRQgPwCgtwiM 3j7OWZdMqoVZfaoN5E2hunA= =JjuT -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html