Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple kernel flaws have been fixed.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
Dan Rosenberg discovered that several network ioctls did not clear kernel
memory correctly. A local user could exploit this to read kernel stack
memory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)
Brad Spengler discovered that stack memory for new a process was not
correctly calculated. A local attacker could exploit this to crash the
system, leading to a denial of service. (CVE-2010-3858)
Dan Rosenberg discovered that the Linux kernel TIPC implementation
contained multiple integer signedness errors. A local attacker could
exploit this to gain root privileges. (CVE-2010-3859)
Dan Rosenberg discovered that the CAN protocol on 64bit systems did not
correctly calculate the size of certain buffers. A local attacker could
exploit this to crash the system or possibly execute arbitrary code as the
root user. (CVE-2010-3874)
Nelson ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: linux-image-2.6.35-903-omap4 2.6.35-903.24 After a standard system update you need to reboot your computer to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1202-1
CVE-2010-3296, CVE-2010-3297, CVE-2010-3858, CVE-2010-3859,
CVE-2010-3874, CVE-2010-3880, CVE-2010-4073, CVE-2010-4075,
CVE-2010-4076, CVE-2010-4077, CVE-2010-4080, CVE-2010-4081,
CVE-2010-4082, CVE-2010-4083, CVE-2010-4157, CVE-2010-4160,
CVE-2010-4162, CVE-2010-4163, CVE-2010-4169, CVE-2010-4175,
CVE-2010-4242, CVE-2010-4243, CVE-2010-4248, CVE-2010-4256,
CVE-2010-4565, CVE-2010-4649, CVE-2010-4655, CVE-2010-4656,
CVE-2010-4668, CVE-2011-0463, CVE-2011-0521, CVE-2011-0695,
CVE-2011-0711, CVE-2011-0712, CVE-2011-0726, CVE-2011-1010,
CVE-2011-1012, CVE-2011-1013, CVE-2011-1016, CVE-2011-1017,
Get the latest Linux and open source security news straight to your inbox.