drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Linux (Aktualisierung)
Name: |
Mehrere Probleme in Linux (Aktualisierung) |
|
ID: |
USN-3880-2 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 ESM |
|
Datum: |
Di, 5. Februar 2019, 06:49 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9568
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1066
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17972
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18281 |
|
Applikationen: |
Linux |
|
Update von: |
Mehrere Probleme in Linux |
|
Originalnachricht |
--===============7147411092641992634== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="LHvWgpbS7VDUdu2f" Content-Disposition: inline
--LHvWgpbS7VDUdu2f Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-3880-2 February 04, 2019
linux-lts-trusty vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in the Linux kernel.
Software Description: - linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise ESM
Details:
USN-3880-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu 12.04 ESM.
It was discovered that the CIFS client implementation in the Linux kernel did not properly handle setup negotiation during session recovery, leading to a NULL pointer exception. An attacker could use this to create a malicious CIFS server that caused a denial of service (client system crash). (CVE-2018-1066)
Jann Horn discovered that the procfs file system implementation in the Linux kernel did not properly restrict the ability to inspect the kernel stack of an arbitrary task. A local attacker could use this to expose sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did not properly flush the TLB when completing, potentially leaving access to a physical page after it has been released to the page allocator. A local attacker could use this to cause a denial of service (system crash), expose sensitive information, or possibly execute arbitrary code. (CVE-2018-18281)
It was discovered that the socket implementation in the Linux kernel contained a type confusion error that could lead to memory corruption. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-9568)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 ESM: linux-image-3.13.0-165-generic 3.13.0-165.215~precise1 linux-image-3.13.0-165-generic-lpae 3.13.0-165.215~precise1 linux-image-generic-lpae-lts-trusty 3.13.0.165.155 linux-image-generic-lts-trusty 3.13.0.165.155
After a standard system update you need to reboot your computer to make all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well.
References: https://usn.ubuntu.com/usn/usn-3880-2 https://usn.ubuntu.com/usn/usn-3880-1 CVE-2018-1066, CVE-2018-17972, CVE-2018-18281, CVE-2018-9568
--LHvWgpbS7VDUdu2f Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAlxY0McACgkQLwmejQBe gfTc9A//bj7rukpwB5ueMDD8jLNymjIte11UT8pZVZhF68C4Fc2wp+touW/zCkIq Z1k2h5Vm0w9LwVqjgJgf7y/reQTn8VYrjTrnxFmD6iF2koQgC2qTLhFYseIGNyMw ObIxV4h0e3MQGm5C0m25rpg1rJmAo8SaIqz1ljQ1KhCWrEYuC7KYRNftjRGw4rEF DOlBwUawxp5L8dgmYixuURFxohWUqcogXO6WN8x01k/yw9UyICybuL9ZB0t10uio zYFyVTHLTMKQs5wYQhXiYeTPz+Xq+2Qm8kIPcHg/QBKHJDVvgO3yMjHckygY4M5S KafZOPPLBGWnBBWk5bxERmk/unAOefd22Yrs7aBJ7ckQB0vFVMCganIVCrSmDpaQ zekwk1EfGdJVrnaxE5j0g5ois5ZHyR8CWtVcgriY4YMNTqzRY9TVdYonyv81VHdV 7i1JZUo3xVQ75zhROieaef/mOWMz8tN88I5udW8rWwctHdyHqnyck+gTLGeOktxU r7FFChU6XAjfLdJcwTBXVfJfT9Oqv7YfPhDJUCy9muYbBXOKoXAIALM6n8FJk3Cn 00v3N77Jc0XUHb9/dpFyuk/qa8quJO9dYyQdQpbfe/Lx1YS6EYLoP+ZdJ0m3UBHh CeYJb96In6xm9VgDqpbII5Nbvv3Eb+PJhctb2LyqSy+nAOqLKI8= =J1Fn -----END PGP SIGNATURE-----
--LHvWgpbS7VDUdu2f--
--===============7147411092641992634== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
|
|
|
|