drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Linux
Name: |
Mehrere Probleme in Linux |
|
ID: |
USN-1205-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.04 LTS |
|
Datum: |
Mi, 14. September 2011, 08:09 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1493
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1770
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2484
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2492 |
|
Applikationen: |
Linux |
|
Originalnachricht |
--===============8479521986439196453== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="rz+pwK2yUstbofK6" Content-Disposition: inline
--rz+pwK2yUstbofK6 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-1205-1 September 13, 2011
linux-lts-backport-maverick vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Multiple kernel flaws have been fixed.
Software Description: - linux-lts-backport-maverick: Linux kernel backport from Maverick
Details:
It was discovered that the /proc filesystem did not correctly handle permission changes when programs executed. A local attacker could hold open files to examine details about programs running with higher privileges, potentially increasing the chances of exploiting additional vulnerabilities. (CVE-2011-1020)
Dan Rosenberg discovered that the X.25 Rose network stack did not correctly handle certain fields. If a system was running with Rose enabled, a remote attacker could send specially crafted traffic to gain root privileges. (CVE-2011-1493)
Dan Rosenberg discovered that the DCCP stack did not correctly handle certain packet structures. A remote attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-1770)
Vasiliy Kulikov discovered that taskstats listeners were not correctly handled. A local attacker could expoit this to exhaust memory and CPU resources, leading to a denial of service. (CVE-2011-2484)
It was discovered that Bluetooth l2cap and rfcomm did not correctly initialize structures. A local attacker could exploit this to read portions of the kernel stack, leading to a loss of privacy. (CVE-2011-2492)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 10.04 LTS: linux-image-2.6.35-30-generic 2.6.35-30.59~lucid1 linux-image-2.6.35-30-generic-pae 2.6.35-30.59~lucid1 linux-image-2.6.35-30-server 2.6.35-30.59~lucid1 linux-image-2.6.35-30-virtual 2.6.35-30.59~lucid1
After a standard system update you need to reboot your computer to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1205-1 CVE-2011-1020, CVE-2011-1493, CVE-2011-1770, CVE-2011-2484, CVE-2011-2492
Package Information: https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.59~lucid1
--rz+pwK2yUstbofK6 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Kees Cook <kees@outflux.net>
iQIcBAEBCgAGBQJOb7p/AAoJEIly9N/cbcAmtCgQAKSWayuXIBiEp2HaC9jJh70f Beu0VccCLQ8UWyaiJfVyy2bGPap2eRM/mUvUSsQKcpggE0l+sdsWmalRZud6Gu8k jlg1PY0N1eiJUtQmnX/XDek5CisIxaocDlYkCVFdCZZL2PTf47vu3TJT88kDKZqr O1YSlijPGY5Eynt4ETZ1zHwHPVXhp/tvjrmhcf/5g4bLZST5JonN5g2NFzBMsbWt DC14i1mWfdQjhxUhecK1Akio1/DIczoAfIaPWUTs489keJzzVlsbbFtmaa4WciMn 5xPQXgt+h+S7btiWvz2qNTGYwEohNkp074T8lpqLjbKYKFW1dptprhx1HmUzQhv9 Gyu90r091W18LX/McP3Q/r8Ac8IfcyO73NDb6S2m7KvCkuzt8k9ZJUvmW85OT3lA YBDCAcE86SthuOAqysAONkyvrrJX1rbr5zaELdpNa9Rfge1+w7tiaXZ/8z8l1Fcw PCAOrOnkWyL4lp2gV1VniVI7By1iD2//4NuqkV4W61gaIRbqtBZ6BIj9dBzj/2gy NQSEWUGLDrOb/mPCRwtDNO7BEh/ev3pGKe74mjhBx/MX1SqblS2fQSDaXDVwN/hC /bvUs97m9rRPbTCoL/ocJkFMqMfnNhUp5kYLhjhBcD+m44i53fd5x+lLWqgD6A8a etU43nd8OusRqrdw1fDg =5G7p -----END PGP SIGNATURE-----
--rz+pwK2yUstbofK6--
--===============8479521986439196453== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============8479521986439196453==--
|
|
|
|