Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 8.04 LTS: USN-1189-1 Moderate: Multiple Kernel Flaws Exploited

ubuntu
Calendar Grey August 19, 2011
Scroller Ubuntu
Ubuntu 8.04 LTS update tackles several kernel vulnerabilities, bolstering the platform's defenses against both internal and external threats.
Multiple kernel flaws were fixed.

Summary

Multiple kernel flaws were fixed.

Software Description:

- linux: Linux kernel

Details:

It was discovered that the /proc filesystem did not correctly handle

permission changes when programs executed. A local attacker could hold open

files to examine details about programs running with higher privileges,

potentially increasing the chances of exploiting additional

vulnerabilities. (CVE-2011-1020)

Vasiliy Kulikov discovered that the Bluetooth stack did not correctly clear

memory. A local attacker could exploit this to read kernel stack memory,

leading to a loss of privacy. (CVE-2011-1078)

Vasiliy Kulikov discovered that the Bluetooth stack did not correctly check

that device name strings were NULL terminated. A local attacker could

exploit this to crash the system, leading to a denial of service, or leak

contents of kernel stack memory, leading to a loss of privacy.

(CVE-2011-1079)

Vasiliy Kulikov discovered that bridge network filtering did not check that

name fields were NULL t...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 8.04 LTS:
  linux-image-2.6.24-29-386       2.6.24-29.93
  linux-image-2.6.24-29-generic   2.6.24-29.93
  linux-image-2.6.24-29-hppa32    2.6.24-29.93
  linux-image-2.6.24-29-hppa64    2.6.24-29.93
  linux-image-2.6.24-29-itanium   2.6.24-29.93
  linux-image-2.6.24-29-lpia      2.6.24-29.93
  linux-image-2.6.24-29-lpiacompat  2.6.24-29.93
  linux-image-2.6.24-29-mckinley  2.6.24-29.93
  linux-image-2.6.24-29-openvz    2.6.24-29.93
  linux-image-2.6.24-29-powerpc   2.6.24-29.93
  linux-image-2.6.24-29-powerpc-smp  2.6.24-29.93
  linux-image-2.6.24-29-powerpc64-smp  2.6.24-29.93
  linux-image-2.6.24-29-rt        2.6.24-29.93
  linux-image-2.6.24-29-server    2.6.24-29.93
  linux-image-2.6.24-29-sparc64   2.6.24-29.93
  linux-image-2.6.24-29-sparc64-smp  2.6.24-29.93
  linux-image-2.6.24-29-virtual   2.6.24-29.93
  linux-image-2.6.24-29-xen       2.6.24-29.93

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1189-1

CVE-2011-1020, CVE-2011-1078, CVE-2011-1079, CVE-2011-1080,

CVE-2011-1093, CVE-2011-1160, CVE-2011-1180, CVE-2011-1493,

CVE-2011-2492

August 19, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.