Preisgabe von Informationen in Linux
ID: | USN-3524-1 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 14.04 LTS |
Datum: | Mi, 10. Januar 2018, 07:06 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754 |
Applikationen: | Linux |
Originalnachricht |
|
--===============2426655419152189834== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="kgyhtahlbgstwyfa" Content-Disposition: inline --kgyhtahlbgstwyfa Content-Type: text/plain; charset=us-ascii Content-Disposition: inline ========================================================================== Ubuntu Security Notice USN-3524-1 January 09, 2018 linux vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel Details: Jann Horn discovered that microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Meltdown. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2017-5754) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: linux-image-3.13.0-139-generic 3.13.0-139.188 linux-image-3.13.0-139-lowlatency 3.13.0-139.188 linux-image-generic 3.13.0.139.148 linux-image-lowlatency 3.13.0.139.148 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://www.ubuntu.com/usn/usn-3524-1 CVE-2017-5754 Package Information: https://launchpad.net/ubuntu/+source/linux/3.13.0-139.188 --kgyhtahlbgstwyfa Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIcBAABCgAGBQJaVVhXAAoJEC8Jno0AXoH0PNkQAKxOsw/JHhcT0N+p8sMLTcIC OwAgoQNwBkzMWYpgAi0zL9/zQ+XVihyvW4+kXibseCMP6RbClxZpqgpZZdT66Ck2 kyDDgHVDs3u8J/78RTggyspGISCZwOE4KyYMX2WH07YIKhOlh5gsKXzUvre5TTkp 9BONS2sEwpAZcUfN5pE7uikENcPu0mpFMaAtIa48UXq4g1+0VAK8L7olfCQwzFtJ UDHSek3nEPzGlwUGyyx6XFZ9lFBtouZi6t0T/CzCLABuITjgtYGJjwgiR6T9d9sN qPWwLQKFOBLiubERcXYuluYJTnfyWPjMskHAGNG9wDdAVgcbRVGZB14JvgeFNbPC UtIO4PNgArj+UiD66+XJlpeXlzxoJZGgbjWoKvg+YwIFlNlKhhtiCPNH88BBKXXR QBSjqN7yIzAvNknJ5IvdTHGxcNNKB/Ur1GZn56v/zm+m8yhGCUXxd2XpHW+/bWOW n4h1dZt5hMOPp8Ba9oKumpVitus07j5P2kmW6vYAvtO+ScqCe6Ckw+zOsCQn9vT9 BFeRLQd34e0zw9wSmxbX0VEE51wSlAFvn4wMJidzjNbgwEuqr2SnVWmkrNdi935l /pZmMeoaCpBNJDWaC8m/YWKkZNsoFSSrpFfRQzqqqvH3CCWd83vPQM5Aj1ENSb8Q K/09jZbTaypWEZL82wMm =3in6 -----END PGP SIGNATURE----- --kgyhtahlbgstwyfa-- --===============2426655419152189834== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce |