Linux Kernel do_mremap Function Boundary Condition Vulnerability Solution:
Avaya has released an advisory to address this issue. Avaya recommends that customers contact their service representative, to upgrade to field load 220. Further information can be found in the advisory located at the following URI:
http://support.avaya.com/japple/css/japple?temp.groupID=&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=158687&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Sun has released a fix to address this issue in the Sun Cobalt RaQ 550. The fix is linked below.
Debian has released an advisory (DSA 423-1) that addresses the issue that is described in this BID for the IA-64 architecture. Further details regarding obtaining and applying fixes can be found in the referenced advisory.
SmoothWall has released fixes to address this issue in SmoothWall Express 2.0. Users are advised to obtain the fixes through the SmoothWall interface. Please see the referenced web page (SWP-2004:001) for more information. Users may download the fixes1 patch by carrying out the following steps:
Go to Maintenance -> Updates on your SmoothWall web interface, and upload
the file called fixes1.
Debian has released advisory DSA 413-1 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released advisory RHSA-2003:417-01 to address this issue. RHSA-2003:419-05 was also released to address Red Hat Enterprise distributions. An advisory (FEDORA-2003-046) was also released for Fedora distributions. See the referenced advisories for additional details.
Guardian Digital has released advisory ESA-20040105-001 for EnGarde Secure Linux. Fixes included in this advisory may be applied with the Guardian Digital WebTool.
Conectiva has released advisories CLA-2004:799 and CLSA-2004:804 to address this issue. Please see the attached advisories for details on obtaining and applying fixes.
Trustix has released advisory TSLSA-2004-01 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Astaro Security Linux has released kernel updates to address this issue in Up2Date 4.018.
SuSE has released security advisory SuSE-SA:2004:001 to address this issue. SuSE has also released security advisory SuSE-SA:2004:003 to address this issue for the 64bit kernel.
An advisory (IMNX-2004-73-001-01) was released for Immunix Secured OS that includes fixes to address this issue. Please see the referenced advisory for details on obtaining and applying fixes.
TurboLinux released an advisory (TLSA-2004-1) that includes fixes for this issue. Please see the attached reference for details on obtaining and applying fixes.
This issue has been addressed in the 2.4.24 release of the Linux kernel. This issue has also been addressed in the 2.6 series as of the 2.6.1-rc2 release.
Debian has issued fixes for the PowerPC and Alpha platforms. See advisory DSA 417-2 in the reference section.
Slackware has released advisories SSA:2004-006-01 and SSA:2004-008-01 to address this issue.
Mandrake has released advisory MDKSA-2004:001 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.
Gentoo has released advisory GLSA 200401-01 to address this issue. Please see the attached advisory for more details. Gentoo fixes can be applied by carrying out the following commands:
emerge sync
emerge -pv your-favorite-sources
# IMPORTANT: IF YOUR KERNEL IS MARKED AS "Manual Update" THEN
# THE PORTAGE MAY REPORT THAT YOU HAVE THE SAME KERNEL ON
# YOUR SYSTEM. YOU SHOULD STILL UPDATE YOUR KERNEL!
emerge your-favorite-sources
# Follow usual procedures for compiling and installing a kernel.
# If you use genkernel, run genkernel as you would do normally.
SmoothWall has released alert SWP-2004:001 to address this issue.
Debian has issued fixes for the mips/mipsel architectures. See advisory DSA-427-1 (in the reference section).
SGI has released a security advisory 20040102-01-U including fixes to address this issue. Please see the attached advisory for more information.
VMWare has released a fix to address this issue in VMWare ESX Server 2.0.1 build 6403. Please see the referenced web page for more information.
Debian has released two advisories DSA-439-1 and DSA-440-1 to address this and other issues. Please see the referenced advisories for more information.
Debian has released DSA 442-1 to provide fixes for s390 platforms. Please see the attached advisory for further information.
Debian has released DSA 450-1 to provide MIPS kernel fixes. Please see the attached advisory for further details.
SGI has released an advisory 20040204-01-U to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information.
Debian has released DSA 470-1 to address this and other issues in the HP Precision architecture. Please see the referenced advisory for more information.
VMWare advisory and fixes available for their ESX server package. Please see th reference section for more information.
Debian has released advisory DSA 475-1 with fixes dealing with this and other issues for the HP Precision architecture.
Sun Cobalt RaQ 550
VMWare ESX Server 1.5.2
VMWare ESX Server 2.0
SmoothWall Express 2.0 beta
SmoothWall Express 2.0 beta6
VMWare ESX Server 2.0.1 build 6403
VMWare ESX Server 2.0.1
Linux kernel 2.4 .0-test3
Linux kernel 2.4 .0-test6
Linux kernel 2.4 .0-test8
Linux kernel 2.4 .0-test7
Linux kernel 2.4
Linux kernel 2.4 .0-test2
Linux kernel 2.4 .0-test11
Linux kernel 2.4 .0-test10
Linux kernel 2.4 .0-test4
Linux kernel 2.4 .0-test1
Linux kernel 2.4 .0-test5
Linux kernel 2.4 .0-test12
SGI ProPack 2.4
Linux kernel 2.4 .0-test9
Linux kernel 2.4.1
Linux kernel 2.4.10
Linux kernel 2.4.11
Linux kernel 2.4.12
Linux kernel 2.4.13
Linux kernel 2.4.14
Linux kernel 2.4.15
Linux kernel 2.4.16
Linux kernel 2.4.17
Linux kernel 2.4.18 pre-8
Linux kernel 2.4.18 pre-7
Linux kernel 2.4.18
Linux kernel 2.4.18 pre-6
Linux kernel 2.4.18 pre-3
Linux kernel 2.4.18 pre-2
Linux kernel 2.4.18 pre-4
Linux kernel 2.4.18 pre-5
Linux kernel 2.4.18 x86
Linux kernel 2.4.18 pre-1
Linux kernel 2.4.19 -pre4
Linux kernel 2.4.19 -pre1
Linux kernel 2.4.19 -pre6
Linux kernel 2.4.19 -pre2
Linux kernel 2.4.19
Linux kernel 2.4.19 -pre5
Linux kernel 2.4.19 -pre3
Linux kernel 2.4.2
Linux kernel 2.4.20
Linux kernel 2.4.21
Linux kernel 2.4.21 pre1
Linux kernel 2.4.21 pre4
Linux kernel 2.4.21 pre7
Linux kernel 2.4.22
Linux kernel 2.4.23
Linux kernel 2.4.3
Linux kernel 2.4.4
Linux kernel 2.4.5
Linux kernel 2.4.6
Linux kernel 2.4.7
Linux kernel 2.4.8
Linux kernel 2.4.9
Linux kernel 2.6
Linux kernel 2.6.1 -rc1