Login
Newsletter
Werbung

Sicherheit: Zahlenüberlauf in ppp
Aktuelle Meldungen Distributionen
Name: Zahlenüberlauf in ppp
ID: USN-2429-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10
Datum: Mo, 1. Dezember 2014, 20:32
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3158
Applikationen: ppp

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8439630704342039559==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="G0TQM86NIS2dSFet332cGvfIJgMclwpAF"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--G0TQM86NIS2dSFet332cGvfIJgMclwpAF
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2429-1
December 01, 2014

ppp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

ppp could be made to crash or run programs as an administrator if it opened
a specially crafted file.

Software Description:
- ppp: Point-to-Point Protocol (PPP)

Details:

It was discovered that ppp incorrectly handled certain options files. A
local attacker could possibly use this issue to escalate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
ppp 2.4.5-5.1ubuntu3.1

Ubuntu 14.04 LTS:
ppp 2.4.5-5.1ubuntu2.1

Ubuntu 12.04 LTS:
ppp 2.4.5-5ubuntu1.1

Ubuntu 10.04 LTS:
ppp 2.4.5~git20081126t100229-0ubuntu3.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2429-1
CVE-2014-3158

Package Information:
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5.1ubuntu3.1
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5.1ubuntu2.1
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5ubuntu1.1
https://launchpad.net/ubuntu/+source/ppp/2.4.5~git20081126t100229-0ubuntu3.1



--G0TQM86NIS2dSFet332cGvfIJgMclwpAF
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUfI5bAAoJEGVp2FWnRL6Two8QALvtwh3m1SXEbzl79icJpIpg
823ZIOzVotw+8Xp9o6qP1tNyKPQN7KdpsvS5ojZRvn4/x2oRdSAdh5zcTIKvkgcw
Am8/RZMezA2c/z8sAgQfNzSMrBwWeR6p1jR7S0d28ZRCHeLuznyGFpUAPpQj0wBw
t/CqEaH3AKUTmXrL1aHpRL441cqA/raR3vH1vHwVOJ3bnZorVGZIJAgw/ojYa2nx
GuC0YFDmOtQMHkeD20sEwMl9IrH/YzavwCb6d6ettsYf8dnA07pQWT6wIGW7X0f9
N0CWbdj+ogtP/ZuS31r04+T11+1zQUzlF/1OUM4occ3viqOv0Nn+JN31L1up59KO
avXJP3eWv0J1OicTgsyTFgExfFBGih3H9MtMOa3q0NQMNTQWlW6wKHtVlhN4MTC9
Q2IdSr+PYAtfYjWjUCjsos0VGuZPNApPQ+kmlJT5JSff3HjdMxNKAzeZkEyXzIx1
/vr2JX6s9PhUoeVr9pFITG/hR1jPYm7ROEsOO2MXpUTs9gJTS89a3HlvKalQ7Ene
0zYT9R9V91rUNby+TwRexLNJS930bNjcC09Z2KRyZFOOtNg3rPQZq8A6AplFJ/Nb
NyO4Sd9+rM24Pv5JsyIykvRxIpkXtrxVA22rzUWv/i7jY+9cGfIcRpJOzJUsbJBM
Vbn1oJzNEdLk83faCG49
=nS3M
-----END PGP SIGNATURE-----

--G0TQM86NIS2dSFet332cGvfIJgMclwpAF--


--===============8439630704342039559==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8439630704342039559==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung