Login


 
Newsletter
Werbung
Sicherheit: Mehrere Probleme in Linux
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Linux
ID: USN-1488-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.04
Datum: Sa, 30. Juni 2012, 09:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2313
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2319
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2375

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--===============6198059226811803269==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="------------enigC283203BF75DC69EE4C4F70A"

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigC283203BF75DC69EE4C4F70A
Content-Type: multipart/mixed;
boundary="------------020001030003040408050509"

This is a multi-part message in MIME format.
--------------020001030003040408050509
Content-Type: text/plain; charset=ISO-8859-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1488-1
June 29, 2012

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Stephan Mueller reported a flaw in the Linux kernel's dl2k network
driver's
handling of ioctls. An unprivileged local user could leverage this flaw to
cause a denial of service. (CVE-2012-2313)

Timo Warns reported multiple flaws in the Linux kernel's hfsplus
filesystem. An unprivileged local user could exploit these flaws to gain
root system priviliges. (CVE-2012-2319)

A flaw was discovered in the Linux kernel's NFSv4 (Network file system)
handling of ACLs (access control lists). A remote NFS server (attacker)
could cause a denial of service (OOPS). (CVE-2012-2375)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
linux-image-2.6.38-15-generic 2.6.38-15.61
linux-image-2.6.38-15-generic-pae 2.6.38-15.61
linux-image-2.6.38-15-omap 2.6.38-15.61
linux-image-2.6.38-15-powerpc 2.6.38-15.61
linux-image-2.6.38-15-powerpc-smp 2.6.38-15.61
linux-image-2.6.38-15-powerpc64-smp 2.6.38-15.61
linux-image-2.6.38-15-server 2.6.38-15.61
linux-image-2.6.38-15-versatile 2.6.38-15.61
linux-image-2.6.38-15-virtual 2.6.38-15.61

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1488-1
CVE-2012-2313, CVE-2012-2319, CVE-2012-2375

Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.38-15.61


--------------020001030003040408050509
Content-Type: text/plain; charset=UTF-8;
name="Attached Message Part"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="Attached Message Part"


--------------020001030003040408050509--

--------------enigC283203BF75DC69EE4C4F70A
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCgAGBQJP7fbAAAoJEAUvNnAY1cPY498QAI7LnpPoJo8efr7qXnfLTzSb
ntdzTU2RnqEIo0XmGIqXWw0KliuKbd5vid0ENNDMixT3wZU4Qw+p4lV30KMoJWJR
IM5nA37872tJa09l9s77thtInBTkyb9fS3/Z5OOTYrQncO40xM04CmU6iFWGfJpd
nCxVUSizHWraRLaT57ydUynC7IVC//uYvvzKyBrlgTj4LMiJtDkrU8wKw4pfY4Gq
ud3bTgp+klfOWF/aDFe6iZ8oQjMA41e39QzaGDmOJnDplot6lxAIyV0gRV0k52LZ
bqfNiWjmzHLQniqn+iaGentfGQZcfYhDj6+2lOkhypQEBW1e4GAFFNYGaKAcM5Ik
06JsMWRK9wCC+RKXb03TmA06wPd6KOGR4UwFyOlsEHdNCEyM3Le5zIaHSKxUeSUb
YobN3LQf4vib22eJoR8PcBNagGncaH2G5QogXu9HC9zUXe+S+HgF9xdW+dytVD/j
ncvNTu5hQlQLtqWAIAujssTwy4x6W/uxighaO6yynkNZVp4VOIxBzVHbPHIV2VmN
hHMbuqpm9OKz5XN6ZnqQuhQg5ClNOmQUfye0InQn7wNSWY3vuiGzfEP08DlEHK08
yB9GhIY/0KJa5dnZVT6g1aWlZf0pJ1/KhdF4yK8iYeSFXBAwXXGp8eL9xClnwWTP
cp3b1LkJMoKADm/7bp5P
=+N08
-----END PGP SIGNATURE-----

--------------enigC283203BF75DC69EE4C4F70A--


--===============6198059226811803269==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============6198059226811803269==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung