Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in Linux
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in Linux
ID: USN-4351-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS
Datum: Mi, 6. Mai 2020, 19:02
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5383
Applikationen: Linux

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============4145302836240878245==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="7P4LQ2vqFZLWYYL0AznqPPLjIxwCBM0IA"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--7P4LQ2vqFZLWYYL0AznqPPLjIxwCBM0IA
Content-Type: multipart/mixed;
boundary="p17cjyq2MfnxeNHCTIEqJhurqqKtiZwF5"

--p17cjyq2MfnxeNHCTIEqJhurqqKtiZwF5
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4351-1
May 06, 2020

linux-firmware vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

The system could be made to expose sensitive information.

Software Description:
- linux-firmware: Firmware for Linux kernel drivers

Details:

Eli Biham and Lior Neumann discovered that certain Bluetooth devices
incorrectly validated key exchange parameters. An attacker could possibly
use this issue to obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
linux-firmware 1.173.18

Ubuntu 16.04 LTS:
linux-firmware 1.157.23

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/4351-1
CVE-2018-5383

Package Information:
https://launchpad.net/ubuntu/+source/linux-firmware/1.173.18
https://launchpad.net/ubuntu/+source/linux-firmware/1.157.23


--p17cjyq2MfnxeNHCTIEqJhurqqKtiZwF5--

--7P4LQ2vqFZLWYYL0AznqPPLjIxwCBM0IA
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl6y6sgACgkQZWnYVadE
vpM/pBAArmi19wtgWUKr9nIzoCO/JRgi4LWkyU5VB+dYSBa9wpxuE4tLZmn0Bh/n
9psRpao/BGd6RMpr4JtW+t5BqaORzwyindJQe7EORJXi5HUkdmFHeYCzFpYxb27h
cVSLDUn+XcP9m7Iopk3zDbO405ak9/d1NwTF0+1x3dUvwmGGh/HuRdro81Hlk8BE
CotoigeSn00JeJ0SkmHpQ0cGMWcYXl+oCwBBHJygJMlSwGrPBgDWyFBdd6L6zeO2
r1gIxLR6CZOpK4TObq0QjZud8X85Uj9GjNR8HS7wQk9jVbOdjdsiz/IuBmExN0Mp
3g2Ktg87jY9c8+F+2v4YFcysP3PCXlGW+EoqQiSK0uk4yRozkvQMoMvErrfgsQ1i
zddBgzvR4W5hYlRyF4rYud6vW1O5IO+En2K29pDHWt9uLPD2ruoJ5MbhC1gnq486
jT6koGIwxYEX/ntPBhU+BXkrd/3zeGEUs/HiAUDE35/N8Gg9J6Mc4RRmtLFYObbZ
t+uxwhnwvYpgxtBAkut6fZwr1d7SXo4JXaRojQ6mD7Cah+B4SxhFu7FHWlBKZq1P
Wby6DTcBItJL18EeX6Bn7TtMXIhC8jTVpXR4y/1ftjfbBE4v+Z200lLpE4Otqo52
M54GEyxi3zmuVjjru8TnVW6mOuj+7HCRDX3wdDR34C3Di7cmIIs=
=lHU8
-----END PGP SIGNATURE-----

--7P4LQ2vqFZLWYYL0AznqPPLjIxwCBM0IA--


--===============4145302836240878245==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============4145302836240878245==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung