Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 10.04 LTS: USN-1805-1 Critical Information Leak Flaw

ubuntu
Calendar Grey April 19, 2013
Scroller Ubuntu
Serious security flaws have been addressed in the Ubuntu kernel, impacting numerous individuals. Prompt installation of updates is advised.
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux: Linux kernel

Details:

Mathias Krause discovered an information leak in the Linux kernel's

getsockname implementation for Logical Link Layer (llc) sockets. A local

user could exploit this flaw to examine some of the kernel's stack memory.

(CVE-2012-6542)

Mathias Krause discovered information leaks in the Linux kernel's Bluetooth

Logical Link Control and Adaptation Protocol (L2CAP) implementation. A

local user could exploit these flaws to examine some of the kernel's stack

memory. (CVE-2012-6544)

Mathias Krause discovered information leaks in the Linux kernel's Bluetooth

RFCOMM protocol implementation. A local user could exploit these flaws to

examine parts of kernel memory. (CVE-2012-6545)

Mathias Krause discovered information leaks in the Linux kernel's

Asynchronous Transfer Mode (ATM) networking stack. A local user could

exploit these flaws to examine some parts of kernel...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  linux-image-2.6.32-46-386       2.6.32-46.108
  linux-image-2.6.32-46-generic   2.6.32-46.108
  linux-image-2.6.32-46-generic-pae  2.6.32-46.108
  linux-image-2.6.32-46-ia64      2.6.32-46.108
  linux-image-2.6.32-46-lpia      2.6.32-46.108
  linux-image-2.6.32-46-powerpc   2.6.32-46.108
  linux-image-2.6.32-46-powerpc-smp  2.6.32-46.108
  linux-image-2.6.32-46-powerpc64-smp  2.6.32-46.108
  linux-image-2.6.32-46-preempt   2.6.32-46.108
  linux-image-2.6.32-46-server    2.6.32-46.108
  linux-image-2.6.32-46-sparc64   2.6.32-46.108
  linux-image-2.6.32-46-sparc64-smp  2.6.32-46.108
  linux-image-2.6.32-46-versatile  2.6.32-46.108
  linux-image-2.6.32-46-virtual   2.6.32-46.108

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1805-1

CVE-2012-6542, CVE-2012-6544, CVE-2012-6545, CVE-2012-6546,

CVE-2012-6548, CVE-2013-0228, CVE-2013-0349, CVE-2013-1774,

CVE-2013-1796

Severity
critical
Lowest
Low
Medium
High
Critical

April 19, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.