Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 10.04 LTS: USN-1808-1 Moderate: Kernel Information Leak

ubuntu
Calendar Grey April 25, 2013
Scroller Ubuntu
Numerous kernel flaws impacting Ubuntu necessitate immediate patches to avert data exposure and system failures.
Several security issues were fixed in the kernel.

Summary

Several security issues were fixed in the kernel.

Software Description:

- linux-ec2: Linux kernel for EC2

Details:

Mathias Krause discovered an information leak in the Linux kernel's

getsockname implementation for Logical Link Layer (llc) sockets. A local

user could exploit this flaw to examine some of the kernel's stack memory.

(CVE-2012-6542)

Mathias Krause discovered information leaks in the Linux kernel's Bluetooth

Logical Link Control and Adaptation Protocol (L2CAP) implementation. A

local user could exploit these flaws to examine some of the kernel's stack

memory. (CVE-2012-6544)

Mathias Krause discovered information leaks in the Linux kernel's Bluetooth

RFCOMM protocol implementation. A local user could exploit these flaws to

examine parts of kernel memory. (CVE-2012-6545)

Mathias Krause discovered information leaks in the Linux kernel's

Asynchronous Transfer Mode (ATM) networking stack. A local user could

exploit these flaws to examine some par...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  linux-image-2.6.32-351-ec2      2.6.32-351.64

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1808-1

CVE-2012-6542, CVE-2012-6544, CVE-2012-6545, CVE-2012-6546,

CVE-2012-6548, CVE-2013-0228, CVE-2013-0349, CVE-2013-1774,

CVE-2013-1796

April 25, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.