drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Linux
| Name: |
Mehrere Probleme in Linux |
|
| ID: |
USN-1220-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 10.10 |
|
| Datum: |
Do, 29. September 2011, 21:18 |
|
| Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1576
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1776
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2213
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2497
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2700
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2723
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2928
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3188
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3191 |
|
Originalnachricht |
--===============2592003569414473774== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-NquPrI3IznYwtSiQFrik"
--=-NquPrI3IznYwtSiQFrik Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1220-1 September 29, 2011
linux-ti-omap4 vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.10
Summary:
Multiple kernel flaws have been fixed.
Software Description: - linux-ti-omap4: Linux kernel for OMAP4
Details:
Ryan Sweat discovered that the kernel incorrectly handled certain VLAN packets. On some systems, a remote attacker could send specially crafted traffic to crash the system, leading to a denial of service. (CVE-2011-1576)
Timo Warns discovered that the EFI GUID partition table was not correctly parsed. A physically local attacker that could insert mountable devices could exploit this to crash the system or possibly gain root privileges. (CVE-2011-1776)
Dan Rosenberg discovered that the IPv4 diagnostic routines did not correctly validate certain requests. A local attacker could exploit this to consume CPU resources, leading to a denial of service. (CVE-2011-2213)
Dan Rosenberg discovered that the Bluetooth stack incorrectly handled certain L2CAP requests. If a system was using Bluetooth, a remote attacker could send specially crafted traffic to crash the system or gain root privileges. (CVE-2011-2497)
Mauro Carvalho Chehab discovered that the si4713 radio driver did not correctly check the length of memory copies. If this hardware was available, a local attacker could exploit this to crash the system or gain root privileges. (CVE-2011-2700)
Herbert Xu discovered that certain fields were incorrectly handled when Generic Receive Offload (CVE-2011-2723)
Time Warns discovered that long symlinks were incorrectly handled on Be filesystems. A local attacker could exploit this with a malformed Be filesystem and crash the system, leading to a denial of service. (CVE-2011-2928)
Dan Kaminsky discovered that the kernel incorrectly handled random sequence number generation. An attacker could use this flaw to possibly predict sequence numbers and inject packets. (CVE-2011-3188)
Darren Lavender discovered that the CIFS client incorrectly handled certain large values. A remote attacker with a malicious server could exploit this to crash the system or possibly execute arbitrary code as the root user. (CVE-2011-3191)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 10.10: linux-image-2.6.35-903-omap4 2.6.35-903.25
After a standard system update you need to reboot your computer to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1220-1 CVE-2011-1576, CVE-2011-1776, CVE-2011-2213, CVE-2011-2497, CVE-2011-2700, CVE-2011-2723, CVE-2011-2928, CVE-2011-3188, CVE-2011-3191
Package Information: https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.25
--×quPrI3IznYwtSiQFrik Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJOhKklAAoJEGVp2FWnRL6TyKcP/1ERpjNElbvfQrs+NtJ8Edam V7qAKAL+a5HQw/Y0f5rGywmz9x9BTeBihh5JRQCCTVYx2MqiskzW/2cWvgm0wy73 926IqJjrFnBq4QmvMhcSxsk+6GxR97xM8UiFcyc3T4GcsuqUjwhc4V+HLVYm89eH OXENdnoSHrSO2KyUFa8xw0ldtILPxsq0pjPdEkCq/pkLYRhNSIPzi7Dyxc8MFKV+ X/6hD0Jmr5LzpSZWyH53kzZ02hEXC0Oa8fb6WDfiADKedMY9JG3NmXj+x9i/WoQ/ 1vpoXgKikMvHwF4wsPsJWb/3QBsR/gSPH8sihHZ5UOPU1IKrQNc+W8+lbksCpDDV iJxK/zjztmzoJTiPXPd149Bs5h5yrjU+NUoYofXx23HnyiB0GSUsh/Ygq1y2jal/ ph63uCxcLRWwuMuroQUWRMwbAAopMc5/GXe9nKZzGsMjZMfUJ55aOg9QCUvg74hm VHUlfEyeSGhvLOzV3u/tPD8TuqZZmCATZ+/1slU7SPgRmevbgTqYJmDl5agfZrFa Yv6tZ1gDcrcOVIG55GN8HS/jDPY84bdjKev+ueCDY3Iiv/8jIZM+AJln19KKjDQb L/iy6St3xscokIgLl+28+7cNySFA+yp8DUDuHemr+2IWNUsMZa16TsuDPraK2nN3 QWY1420onANUp84QtvAo =tREx -----END PGP SIGNATURE-----
--=-NquPrI3IznYwtSiQFrik--
--===============2592003569414473774== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============2592003569414473774==--
|
|
|
|