Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 10.04 LTS: USN-1664-1 Critical: linux-ec2 Firewall Bypass

ubuntu
Calendar Grey December 13, 2012
Scroller Ubuntu
Ubuntu Security Notice USN-1665-1 tackles a severe vulnerability in the ec2 kernel that permits unauthorized access through the firewall.
The system's firewall could be bypassed by a remote attacker.

Summary

The system's firewall could be bypassed by a remote attacker.

Software Description:

- linux-ec2: Linux kernel for EC2

Details:

Zhang Zuotao discovered a bug in the Linux kernel's handling of overlapping

fragments in ipv6. A remote attacker could exploit this flaw to bypass

firewalls and initial new network connections that should have been blocked

by the firewall.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  linux-image-2.6.32-350-ec2      2.6.32-350.58

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1664-1

CVE-2012-4444

Severity
critical
Lowest
Low
Medium
High
Critical

December 13, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.