Multiple flaws fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-1146-1 June 09, 2011 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 8.04 LTS Summary: Multiple flaws fixed in the Linux kernel. Software Description: - linux: Linux kernel Details: Kees Cook discovered that some ethtool functions did not correctly clear heap memory. A local attacker with CAP_NET_ADMIN privileges could exploit this to read portions of kernel heap memory, leading to a loss of privacy. (CVE-2010-4655) Kees Cook discovered that the IOWarrior USB device driver did not correctly check certain size fields. A local attacker with physical access could plug in a specially crafted USB device to crash the system or potentially gain root privileges. (CVE-2010-4656) Goldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly clear memory when writing certain file holes. A local attacker could exploit this to read uninitialized data from the disk, leading to a loss of privacy. (CVE-2011-0463) Jens Kuehnel discovered that the InfiniBand driver contained a race condition. On systems using InfiniBand, a local attacker could send specially crafted requests to crash the system, leading to a denial of service. (CVE-2011-0695) Rafael Dominguez Vega discovered that the caiaq Native Instruments USB driver did not correctly validate string lengths. A local attacker with physical access could plug in a specially crafted USB device to crash the system or potentially gain root privileges. (CVE-2011-0712) Timo Warns discovered that LDM partition parsing routines did not correctly calculate block counts. A local attacker with physical access could plug in a specially crafted block device to crash the system, leading to a denial of service. (CVE-2011-1012) Timo Warns discovered that the LDM disk partition handling code didnot correctly handle certain values. By inserting a specially crafted disk device, a local attacker could exploit this to gain root privileges. (CVE-2011-1017) Tavis Ormandy discovered that the pidmap function did not correctly handle large requests. A local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-1593) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 8.04 LTS: linux-image-2.6.24-29-386 2.6.24-29.90 linux-image-2.6.24-29-generic 2.6.24-29.90 linux-image-2.6.24-29-hppa32 2.6.24-29.90 linux-image-2.6.24-29-hppa64 2.6.24-29.90 linux-image-2.6.24-29-itanium 2.6.24-29.90 linux-image-2.6.24-29-lpia 2.6.24-29.90 linux-image-2.6.24-29-lpiacompat 2.6.24-29.90 linux-image-2.6.24-29-mckinley 2.6.24-29.90 linux-image-2.6.24-29-openvz 2.6.24-29.90 linux-image-2.6.24-29-powerpc 2.6.24-29.90 linux-image-2.6.24-29-powerpc-smp 2.6.24-29.90 linux-image-2.6.24-29-powerpc64-smp 2.6.24-29.90 linux-image-2.6.24-29-rt 2.6.24-29.90 linux-image-2.6.24-29-server 2.6.24-29.90 linux-image-2.6.24-29-sparc64 2.6.24-29.90 linux-image-2.6.24-29-sparc64-smp 2.6.24-29.90 linux-image-2.6.24-29-virtual 2.6.24-29.90 linux-image-2.6.24-29-xen 2.6.24-29.90 After a standard system update you need to reboot your computer to make all the necessary changes. References: CVE-2010-4655, CVE-2010-4656, CVE-2011-0463, CVE-2011-0695, CVE-2011-0712, CVE-2011-1012, CVE-2011-1017, CVE-2011-1593 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.24-29.90 . Several vulnerabilities within the Linux kernel are present in Ubuntu 8.04 LTS. It is crucial for users to apply updates for enhanced security.. Ubuntu Kernel Issues, Security Flaws, System Patches, Kernel Updates, Linux Security Fixes. . LinuxSecurity.com Team
Dan Rosenberg discovered that multiple terminal ioctls did not correctly initialize structure memory. A local attacker could exploit this to read portions of kernel stack memory, leading to a loss of privacy. (CVE-2010-4076, CVE-2010-4077) [More...]. ==========================================================Ubuntu Security Notice USN-1092-1 March 25, 2011 linux-source-2.6.15 vulnerabilities CVE-2010-4076, CVE-2010-4077, CVE-2010-4158, CVE-2010-4162, CVE-2010-4163, CVE-2010-4242 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: linux-image-2.6.15-57-386 2.6.15-57.94 linux-image-2.6.15-57-686 2.6.15-57.94 linux-image-2.6.15-57-amd64-generic 2.6.15-57.94 linux-image-2.6.15-57-amd64-k8 2.6.15-57.94 linux-image-2.6.15-57-amd64-server 2.6.15-57.94 linux-image-2.6.15-57-amd64-xeon 2.6.15-57.94 linux-image-2.6.15-57-hppa32 2.6.15-57.94 linux-image-2.6.15-57-hppa32-smp 2.6.15-57.94 linux-image-2.6.15-57-hppa64 2.6.15-57.94 linux-image-2.6.15-57-hppa64-smp 2.6.15-57.94 linux-image-2.6.15-57-itanium 2.6.15-57.94 linux-image-2.6.15-57-itanium-smp 2.6.15-57.94 linux-image-2.6.15-57-k7 2.6.15-57.94 linux-image-2.6.15-57-mckinley 2.6.15-57.94 linux-image-2.6.15-57-mckinley-smp 2.6.15-57.94 linux-image-2.6.15-57-powerpc 2.6.15-57.94 linux-image-2.6.15-57-powerpc-smp 2.6.15-57.94 linux-image-2.6.15-57-powerpc64-smp 2.6.15-57.94 linux-image-2.6.15-57-server 2.6.15-57.94 linux-image-2.6.15-57-server-bigiron 2.6.15-57.94 linux-image-2.6.15-57-sparc64 2.6.15-57.94 linux-image-2.6.15-57-sparc64-smp 2.6.15-57.94 ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number,which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. Details follow: Dan Rosenberg discovered that multiple terminal ioctls did not correctly initialize structure memory. A local attacker could exploit this to read portions of kernel stack memory, leading to a loss of privacy. (CVE-2010-4076, CVE-2010-4077) Dan Rosenberg discovered that the socket filters did not correctly initialize structure memory. A local attacker could create malicious filters to read portions of kernel stack memory, leading to a loss of privacy. (CVE-2010-4158) Dan Rosenberg discovered that certain iovec operations did not calculate page counts correctly. A local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2010-4162) Dan Rosenberg discovered that the SCSI subsystem did not correctly validate iov segments. A local attacker with access to a SCSI device could send specially crafted requests to crash the system, leading to a denial of service. (CVE-2010-4163) Alan Cox discovered that the HCI UART driver did not correctly check if a write operation was available. A local attacker could exploit this flaw to gain root privileges. (CVE-2010-4242) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 3063403 497f2f0eda80b5d987a7753ec51a6b74 Size/MD5: 3041 16c2feef25902ec8c0b46e6aa2e36c1f Size/MD5: 57403387 88ab0747cb8c2ceed662e0fd1b27d81d Architecture independent packages: Size/MD5: 5172048 313c5e187d63d0ddf27527b6b32f01ea Size/MD5: 98736 4244d05f746c994d47c448b547ba4932 Size/MD5: 44745964d86a73089b4b0270e0986504f381e3d8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 22344 b6743583cd6407aa230211666a2d0c92 Size/MD5: 44778 db3d5f43c1f6e49a0ade6e6cf153a1ef Size/MD5: 2310 4ddf93cbe21e87ff5352637d94769597 Size/MD5: 36292 4305424c7af2c3779449414e933281c2 Size/MD5: 102366 61f38cefc0ba4bd912c9281b581272af Size/MD5: 38896 f217272988a7c7ec8e883b7b3d4232a6 Size/MD5: 49162 4a871cf139d68991be5563239a61ff88 Size/MD5: 176626 916f6eb88064466b27a36b6e17ff545a Size/MD5: 36780 8d0822a592160721d424ebfe888307d8 Size/MD5: 142348 af2c0c8068f8482e3dfd858db3c5874c Size/MD5: 51066 07e4978ae527aac8e8daad9697abe140 Size/MD5: 140710 b0aa2d3dbc4f8b354ce615c92a002e23 Size/MD5: 287600 f83df94ed289ba25fda130c6aad0debd Size/MD5: 97778 40fdb5850567ca1e4719b08d0a6035a3 Size/MD5: 1654194 69c3d5a26269069555d7bdcf6b9472de Size/MD5: 872664 e863b64464efce29b3188e09e50b7b45 Size/MD5: 872364 5775d397a4a0584dd8244e3cc643d8ee Size/MD5: 872086 1466745e7c2aca14964c1261ba67080e Size/MD5: 871748 dc535ba502d25a97f71d5938a14baa69 Size/MD5: 6928258 5f31f9b7b8c93b98e6e5f9a81f803e9b Size/MD5: 20820686 6f51f56b67c235a652f8ff18ef3c9697 Size/MD5: 20801340 69cc7a1180691e7f88c2a422f72f0894 Size/MD5: 21636466 3c245ceb627fb960cd1f63b13ba99215 Size/MD5: 19905058 679a9f6ffb3b3baba1add1e9c6f2b2dc Size/MD5: 15626 15e1a6a56256d962ca98db5585bb719d Size/MD5: 240374 f276a6e767da5a3bcfca318099e14420 Size/MD5: 202680 4098813ed7b7c9859f68352acbfe15da Size/MD5: 1048608 c8d4ea0abe354cec04bfaeefac080ae6 Size/MD5: 1543784 c41a766a328570168b12c9c8c115f00f Size/MD5: 161690 981c2676e3fa1f2a517d36b3f4fd8f61 Size/MD5: 9830 6475b2764c7f8ab635a121ae09c1ca0b Size/MD5: 80870 f1a3117afbc98d3292c37d2c4f527704 Size/MD5: 49294 574b5be4a9075ee35c77f2c57278fc54 Size/MD5: 35166 f2fe865081699e9bb68b88f1a7a7f585 Size/MD5: 70900 3203803ceaf9e9d05f471d5eb85139f2 Size/MD5: 6222 b9c32e55adb315f97c6c5bd6b8d091bf Size/MD5: 9060 c3ff055485b8b8b85c65dd8a7293c451 Size/MD5: 57922 e128a5979f6ee706ba0a081761680581 Size/MD5: 123364 de1732e1119d9a7c42c9f40008a39db4 Size/MD5: 101080 04b1e5d5614cd0a7663a5fc923ceda49 Size/MD5: 79276 44d649f9aea098e41469e8252ce7436d Size/MD5: 1595476 39254e6fa3fdf5b22aa72ff9f0000898 Size/MD5: 72344 a67eddeab3572b6920ce5e697370b294 Size/MD5: 12672 2d487a7050857c6370120f948c3b64b6 Size/MD5: 33808 705ea3a6716bae4b3632ae29d40c2f47 Size/MD5: 138604 31fa320f7bd967fa6f8aeda773946005 Size/MD5: 38934 c2bbef6ae46d4cebddb4c664d846d2cb Size/MD5: 278764 1537a3b69361ae06c70b7423001ce33a i386 architecture (x86 compatible Intel/AMD): Size/MD5: 18976 e149d181422d8f56dece3fc565d7cfb1 Size/MD5: 43490 2648db7ecb0e92a565d7bb066afc933b Size/MD5: 105208 5b6b2d6962d0ffb2204663b860c3e48b Size/MD5: 2288 38565be399d52f8e98dbcdf2b5a0c511 Size/MD5: 34572 f7a098263ec37a41fee6a1e80e36d669 Size/MD5: 97044 4bd6273f331dca735522b6027ad1c52d Size/MD5: 37138 707a7437cb94cecab52c1d5323d0fa6b Size/MD5: 44120 207921cfdfcc6a65040dc3daf32477db Size/MD5: 167730 bac22cb3c7f1bccd155eb4882e9f61d6 Size/MD5: 33954 04fee833ec278aba4263c3748ba5d386 Size/MD5: 137974 1001ab93bc8ab783778538d8c4dc6693 Size/MD5: 46890 3493e842e51e6fb2e96f84b7b0aab799 Size/MD5: 133154 aacadd11b65d0a964bef65d0d2950fb8 Size/MD5: 273744 14411276e82f1fd02c27f2548c23924b Size/MD5: 102296cbe9ddd056894f57c7e40e9dfd9c0033 Size/MD5: 1598742 6c6debf5eabb1b0739876129ddbe306b Size/MD5: 860524 804f5a1555e86ffc01d13db67e17e497 Size/MD5: 861994 7ae466d9f200b639d316a28828fa57ca Size/MD5: 859668 c70de1b55555b667e44c4c66dfd8e470 Size/MD5: 865358 3b5bcd4b4ec96d937f10fe1cd691affc Size/MD5: 862012 3c29850c40230a3da76ed417218bf4a1 Size/MD5: 6920468 213d0f07e6273fda7091a809ad6db951 Size/MD5: 21725620 837dc0a056ab32731094e2a9486f8143 Size/MD5: 22520958 d4176023a311f364c0bf4bd4b7f37b2f Size/MD5: 22268022 845c97bac8f237ac4aa5ca6eab1d8b75 Size/MD5: 23626124 7acbde3a4cd8a5f7848679a8b43aa4c1 Size/MD5: 23177710 b0350f5b4dbaaec8d002d210808a0ba4 Size/MD5: 15514 e1dc7140df764b069ccba3f9db22b15e Size/MD5: 238510 b39bc16ce90bf44b29db3ad6c93bba67 Size/MD5: 197142 30198bbe48fa07945d61a5a300d8003e Size/MD5: 1048404 ed335b24224bf8637256f80e3f3804e5 Size/MD5: 1741546 09f3444c02342e2813f394ddcee04ca9 Size/MD5: 160888 8dd6410b8cc67a245ed7306934887a54 Size/MD5: 9166 4ab7f4bf171292a8d30739e29326fb6d Size/MD5: 76480 317f90fd47b7809688599b18924c921f Size/MD5: 53546 e1ae38fd9364d0c3d98667ca7aab73be Size/MD5: 33050 5fa34f31311ac03bed36ac1b8e0d0b25 Size/MD5: 85626 b44a167b864d3ddb43a51214193ce3c1 Size/MD5: 6022 3db1fdff51f5efa29e3cfdbed76f3817 Size/MD5: 8762 99cc775b320fa5d9aebe86165e829ff9 Size/MD5: 53634 e24b0b1e44de87f64667fb0461d659f2 Size/MD5: 130962 cd5103956fc2893de9ac21444d5afb60 Size/MD5: 98468 cb4299ca0661e8ea7ad8c67790c02e8b Size/MD5: 77210 ef0fe3149daaa0f6c4bbff58bc9f74b1 Size/MD5: 1768890 b5eae10f0c3ee705f0804f49f332e1a5 Size/MD5: 69608 6781ceb02ddc7a4a0a77c240353b1ab4 Size/MD5: 117787e4eaf6f136971e5cf98518aa3da90e4 Size/MD5: 36108 a9f582491e9494a038f7b03b5987cdbd Size/MD5: 132752 4800c50b8ab89a32fde64757f41fc6a9 Size/MD5: 38576 d0be72bb4654c64ed08c56e32045cf6c Size/MD5: 298968 5701eae7c83de64f616e9b44f7c50860 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 23736 e84833f4d6e90a9c4bda7f8b43d1618f Size/MD5: 26008 b13efa08f995c460ccab4dcd311ce228 Size/MD5: 49316 790be7338f33ec4b1ba592d111d20fe8 Size/MD5: 51540 bdef3235416444b12369867fb5fcc12d Size/MD5: 2310 f1109f4b7ac0d74b14d11d81dbd2eaa6 Size/MD5: 2480 be068c974a6b834264d1eec6731bd6d5 Size/MD5: 40310 45562480c7775e6ceac8a8b7d924748a Size/MD5: 43844 b31254489e0cbb6804a1b3e61b07bb05 Size/MD5: 112604 8ccbc1534cb0d4754e937c7b2c07461a Size/MD5: 120736 979bc6e074b013ff641db0fdd12dfa46 Size/MD5: 40908 5ef54f0507eaa2324ed7a145442fe16a Size/MD5: 46000 12f3661cd115186dba68297e6023dc9e Size/MD5: 29030 8b12cd5c03b850e45ddefb2bb135f90a Size/MD5: 29896 e78215c452e69913b28be631b275eca3 Size/MD5: 211406 254ae0a74a772d794a86926207ecbd24 Size/MD5: 225180 30324727d8c136a14921be9a84e9cf3a Size/MD5: 45056 b625d96eb31938287283d57430c666b6 Size/MD5: 40220 90da4c27d29d3d535d67853fce304a9d Size/MD5: 1940 72446c2ed7aa102069f30f170dcbddeb Size/MD5: 2202 4da571f1e8cd0ab57b7db944647bfa80 Size/MD5: 80768 0ffa194488e99673547a55f0c7c575e9 Size/MD5: 86142 ac7876e0a6822a1f0f78cc5e4632c924 Size/MD5: 111582 17139394d803df78ad30f3b2f53af16e Size/MD5: 125744 77c6500cf4bb82e2efb5fdf65b21b105 Size/MD5: 53424 418168df4df1519b109494867cf50917 Size/MD5: 58492 b36d1261481b4933419c312529090a55 Size/MD5: 147966 2db7211efcb511cba2d0bc0305b2381f Size/MD5: 161900 4c37e6e031b6cdcf13766cdd3bd6367d Size/MD5: 318398 bc5d3031144c005d36a221ba2cdaaeed Size/MD5: 288040 2dcc4420ad066ff06e4a168dcaf59086 Size/MD5: 115880 d218e6eb4df6dd019674aecb49288e21 Size/MD5: 116596 03dc6ce9ff271e038d0d3dc3b53bd12f Size/MD5: 1925338 21a2f9abbf8dd6a29bfdf44311a82537 Size/MD5: 2449528 5d01c382d0b7d51b4f3a63976a5e4053 Size/MD5: 870724 2b92309a99550d2cbde05d112e083e87 Size/MD5: 871552 83c8d92171b85b8ea11df175c080b545 Size/MD5: 869782 7c0c53d5a8bfa0f7782359644b9754d5 Size/MD5: 6949026 d18e3075155ae9fb6be80ffdf811d75e Size/MD5: 22785538 273cee8a92b8891dee4bcad13d30910a Size/MD5: 23693880 004530b7dd6a0c9ee5d2b4bbb092fbf9 Size/MD5: 22367116 ee2cf2f49e98f72ff744d4b2aed318b7 Size/MD5: 17780 1bb73e8da2181392d30b816aec5d922c Size/MD5: 17390 113325120369e6f66ebc63f5b1eb0c37 Size/MD5: 261370 3fabc0532c1cd09c779b1ee81d8ee936 Size/MD5: 282622 e7bf901923fade46e3a348c1d01b9cde Size/MD5: 227834 cbec1575608920aacf374a5d67b750f7 Size/MD5: 248948 63ee5cf81be86bae8282fab37b7393c1 Size/MD5: 1048474 28d4204273e26321f740918f634789b4 Size/MD5: 1048606 9a84e753d7fe407cf3ed0254a20b16bc Size/MD5: 1738656 43d12d7e7b865eccc8ad9faa29753b6c Size/MD5: 1878316 5971b47ac40ecfb7ab0e8635f165b4d2 Size/MD5: 250838 6a22327beb0406d5310b6d3df25c8163 Size/MD5: 233536 67eb1bab1b5b209115b9ac8fb3f3c144 Size/MD5: 13060 4599dd520df1ebb9870410262f94cc78 Size/MD5: 13536 3b7047ce4240b2b4c9a7b02f5994a057 Size/MD5: 84802 c31da92d25c55eeb69d645981110cdb2 Size/MD5: 52210 97ba4dd71eb662880f7e20a6522adb16 Size/MD5: 73934 d504ab67e2d79bf65a9adbf100d1fa3a Size/MD5: 85848 33056e4e5174979e7d3990a558a6a364 Size/MD5: 6622754765678e2c5363c4c0701bc6a1a3d3 Size/MD5: 7060 4c661d14b3157aa00298ca84e85becb2 Size/MD5: 60376 8b7be8da2fd029cb3de7c9053c7b75f1 Size/MD5: 70422 35a575c88d788ae37d15436daf93e78a Size/MD5: 128554 d66102f63b03577c01e269ba75d59d9f Size/MD5: 157958 ae64d24adb27804690cadace4335c2d6 Size/MD5: 108154 81868f76a2a98055793c303d9cc31d38 Size/MD5: 126140 7e17543f625158c18b6df3ad434411f6 Size/MD5: 87296 fbedc9c7e07c18f0af2005b436fee9c7 Size/MD5: 93362 95b84c9064109171c3e00b3ea11fcc13 Size/MD5: 2014750 930a89bb7a2f64453002a4e8bcdfaad3 Size/MD5: 1988810 98e65b41974cc2bfa0a76bb9132a0981 Size/MD5: 104192 c131fd75fc7b5cde91638c3d66165928 Size/MD5: 115840 0a221bc12f9216a943277b93da9df835 Size/MD5: 12774 7d9ccabf3c0e1a79434df28bbffa81e1 Size/MD5: 14472 a88002d863e35e0afaa6e6b1fdb9d29c Size/MD5: 39954 93032d86cb3803da5c6df9ddd5e228cb Size/MD5: 41544 f923cebabeecbc32883fe3c0af0c107d Size/MD5: 149448 bc041b1af7d0f1f4830c42e2c26e32fc Size/MD5: 168184 855018f74765cfbd59851bcb976c1d9d Size/MD5: 42322 8e48571adbc260dacff07e8883c84a9c Size/MD5: 44922 854aa12ed95c6f672758ad37d1a5b2e0 Size/MD5: 320160 87d5e0c3f3692b1e966ef61775f20abf Size/MD5: 324840 f3b8aaeeca5ed502f8d496b0d33fe603 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 50478 d4b193569ece5263d80f644ce4702daf Size/MD5: 2356 5a26bf06252adab2d414c9f43c637705 Size/MD5: 40380 bbc1a4f4ad41ab8826c46894a8ca2cff Size/MD5: 110558 f21cb35f3077151455ddc5f3b263222a Size/MD5: 41214 03bcfd606253d41ed030b49926b2f157 Size/MD5: 104226 abd17c57cf9db3a0247dd4da0fcbc5f8 Size/MD5: 7438 df96b5caa09b033bb5ca44ba38426d6b Size/MD5: 149304 5c7b9914c5082845d8bb366cb667370e Size/MD5: 1713036 0545406d9943600ba6b73b06e39e9889 Size/MD5: 773648 39f0779ed31fab90487260aa77639454 Size/MD5: 773182 61d17c61bd4be88584bd179d96dfc1ad Size/MD5: 6965544 9472ffe2850fc0099d3ca5092c4d0833 Size/MD5: 15018376 dde44083bd3d12c205c80daf705deb67 Size/MD5: 14834706 92ecf40a304445eac63274529dd53378 Size/MD5: 7438 fc6a727cfe8fa9388715d2d5c404ecea Size/MD5: 248746 0e654a6ea623d346ccae16daff665d0c Size/MD5: 212538 3e568621ec5cb36f64c59d928a82d104 Size/MD5: 1048472 042e58eb479630d1d81e4e0881deafce Size/MD5: 1482446 16536c2ea2742c3969430ec42b32fd86 Size/MD5: 10116 244d77c7be67d28577bd56bdef81bfa4 Size/MD5: 40178 aaf251da1360737a7d6b684121f4bc08 Size/MD5: 9366 b384ebcc8851d51df41e0ae3094b9edd Size/MD5: 61404 97a1dfcc40388d68784d3fb7d4af725c Size/MD5: 163278 0c66d6b87ca34385c1a55d78894073b4 Size/MD5: 64092 6c924d18cc346cdea19e1c124566bc07 Size/MD5: 1235388 937227ca71dc0345c694cfb0b4844e14 Size/MD5: 59310 63c70c0e5388458477951e7e97baadf0 Size/MD5: 37432 3f107b7ae35f9600fef78914e982927d Size/MD5: 280102 7367f91313f10dff95378964d37c8313 . Several kernel vulnerabilities identified may result in data exposure and service interruptions. Ubuntu users are advised to apply updates.. Linux Kernel Issues, Ubuntu Security Update, Privacy Breach, Denial of Service, Kernel Module Rebuild. . Severity: Important. LinuxSecurity.com Team
It was discovered that the IcedTea plugin did not correctly check certainaccesses. If a user or automated system were tricked into running aspecially crafted Java applet, a remote attacker could read arbitraryfiles with user privileges, leading to a loss of privacy. (CVE-2010-2548,CVE-2010-2783) [More...]. ==========================================================Ubuntu Security Notice USN-971-1 August 16, 2010 openjdk-6 vulnerabilities CVE-2010-2548, CVE-2010-2783 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 9.04 Ubuntu 9.10 Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 9.04: icedtea6-plugin 6b18-1.8.1-0ubuntu1~9.04.1 Ubuntu 9.10: icedtea6-plugin 6b18-1.8.1-0ubuntu1~9.10.1 Ubuntu 10.04 LTS: icedtea6-plugin 6b18-1.8.1-0ubuntu1 After a standard system update you need to restart any Java applications to make all the necessary changes. Details follow: It was discovered that the IcedTea plugin did not correctly check certain accesses. If a user or automated system were tricked into running a specially crafted Java applet, a remote attacker could read arbitrary files with user privileges, leading to a loss of privacy. (CVE-2010-2548, CVE-2010-2783) Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 130876 791d1430ba78b206019b9f928ce6f655 Size/MD5: 2368 857c617e3aba466ebb3ede1dfb7ecadd Size/MD5: 68315117 09ff345836841ae848e30da7ab089c87 Architecture independent packages: Size/MD5: 19757840 8f729abfec60da0e603f96cb2cc3da75 Size/MD5: 5804748 8b55b8ccc2894ea6c9201d5d516c3f49 Size/MD5: 26750044 be4d3e01798ad02eacf9148aa97403d9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 371434d9f6a654460bee98a1bcebdfa514caaf Size/MD5: 84162 2387e32894e2ec9f6751168521d98794 Size/MD5: 91703024 cd725d0e84441863074a630dda99f12c Size/MD5: 2360718 791d3c5321dcac6e6b905627ba88c954 Size/MD5: 11020712 e98eba6a02114d9aa57ea151b15437e3 Size/MD5: 25454558 193bc4d11a6d637af779d545e56ca612 Size/MD5: 269058 065b3f5b69a853f4e02f0d466bcddd3d Size/MD5: 2077082 777cc86837e896ab81b2319ed5ee8a16 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 344412 5698e4578958682c58edfd30833a4f2a Size/MD5: 78448 baf25cdcdf9dd797dbfe4319d5890300 Size/MD5: 156742426 3549e656235f5cafd64319d34e0e272a Size/MD5: 2342312 98ee50c02d527484482c205b0d3349a9 Size/MD5: 11036544 0cf2e6e20693daa77abc0a450a4d8bf6 Size/MD5: 27136396 8a366351c0b2edecd7f81a31d60eb4e0 Size/MD5: 256316 588382d8931879923649109b21c431c6 Size/MD5: 1778844 a66bd1812a85b1939540492bbc325470 lpia architecture (Low Power Intel Architecture): Size/MD5: 344032 7fbe1173fdecf89ce9383e2e5386975f Size/MD5: 80588 2a906c89a2be99b0c88ba741114a8f20 Size/MD5: 156922662 b2661dcf2de30b786dbc2bd06c3cc3e5 Size/MD5: 2338458 5641e6a3bcb78845e2104324df9afdbc Size/MD5: 11031000 39e085680d50ccdf87d8ff9f29ab892f Size/MD5: 27163780 66cdc95788742bf1ac268727dd35790d Size/MD5: 252120 1d6758b3c71711b664217abe95d3b0ba Size/MD5: 1764000 f4194bda6f6770e4f307e7ee4c45491f powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 361276 4d891c9fea1b788d356a6c5d52100f5a Size/MD5: 86120 4462079e967b119270e5b91a14d5742f Size/MD5: 42110908 04d5f7a0f75ae6f9bd5b79401fc7638b Size/MD5: 2405782 dfc6b0ee129d03f35d78d48fcc3d36c9 Size/MD5: 8983948 8e3219bac8e85c585b9f81ee8a10adef Size/MD5: 23853036 3c1fc6bcfacbbfae8ac650d18de278e7 Size/MD5: 2853709cbcd2fbf9b1a97545211b2ca0d26c2e sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 117982528 798eefbea0246c5379627e728befeb8e Size/MD5: 2360214 69b479bfc2c0e996b722ae830380794e Size/MD5: 10892850 924f63cb5c7806ad6365987c3edeeef8 Size/MD5: 26820672 c193c769fc933685f5d86c6fccfeab80 Size/MD5: 240472 c9ed65650c1478c4ed5270868307180d Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 130891 1734b5a132871cdba9be7054ca2a830b Size/MD5: 2441 445311afba6f224005a31dc5760bf925 Size/MD5: 68315117 09ff345836841ae848e30da7ab089c87 Architecture independent packages: Size/MD5: 19757312 063e2ba9aec17c1ec13cc9f6d36e00a4 Size/MD5: 5919490 a62084483561e0981818280ee27d17e5 Size/MD5: 26753076 892f77124bcd8d809adb154f42bf2a34 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 374770 a7a285cc34a1ecaeb00d116a181bdd33 Size/MD5: 83646 46d36d7a3e6913d2c53eaddce4ab35fd Size/MD5: 104636522 fbac64c41aa18cb1730965af5800e3fb Size/MD5: 2362162 314d809d971501f6f1e2b31d4b6addd8 Size/MD5: 11027452 830cd2e1fc986b9446e9d130504e0ce2 Size/MD5: 25535628 826efacd5107e23521f3edbedc7350ce Size/MD5: 270734 f43528b41405e15b90132ff207a30917 Size/MD5: 5421236 5c804ad8cc90e7fc482463e7c785ca62 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 344366 b5bddd0fbd2e46ab5403ed3fdcd01526 Size/MD5: 79220 d1702fd4baf9cb41518661fa34785ba2 Size/MD5: 168911858 06783bfcfc1d9fce6318a33037b626e3 Size/MD5: 2349054 001f278047147c7b7866a290296e0426 Size/MD5: 11028396 a71b5d3e17e5ef2e11a98c8ee755861f Size/MD5: 27261422 fb7c83ee339340a95f4171414400ff7c Size/MD5: 258532 b8cf6ac78110108f8a10136b6673432b Size/MD5: 4927638 a06b23b669a3f6aae8dbbcda9958e514 lpia architecture (Low Power Intel Architecture): Size/MD5: 34552625479f569e839e11077dcba216c049ed Size/MD5: 81880 7d3fd58921340e708d2404ae19b4cbf0 Size/MD5: 169074900 790389ce36b5a7a493cf0ab0fd208011 Size/MD5: 2346184 42d06f9d50ed422b131eb4cd0ff8e498 Size/MD5: 11027082 06a3a82a3425ffd6e786bfadadae9350 Size/MD5: 27304448 dfc43c6520133e1f2d5a8428925aa974 Size/MD5: 254722 e4f08b47046de1452450a93bb1768056 Size/MD5: 4918674 184acfca6b59b9fffe5ffb01bf1e69ad powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 365158 2d4b349c8e5285bcab3248f9fb9b6795 Size/MD5: 82928 6113d770e20edeba5642ed9052960f6e Size/MD5: 87504726 8af2e0fdf3062a7611d8008bea08c36d Size/MD5: 2363656 0360a4f2392a82e3f9eb90d8bb29ba7a Size/MD5: 8978030 14f3c03f339d641ed9bf208f2653d11e Size/MD5: 23887824 b836e540cef02ea9bd7ab3229eb2d642 Size/MD5: 277976 0a4812e2f67506f413e335cf3a099afe Size/MD5: 4746666 ccae053becd0d4d0077d6413c55dbcff sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 79616 10c2f75d59c8c840f3781df6d3d76e16 Size/MD5: 119532534 d21e3f06e910babb373617d3598f5eec Size/MD5: 2363126 9501f58ffb49a87cf6b737cb58e81b4e Size/MD5: 11048288 ecb19f0faf13b17ce665899552704f99 Size/MD5: 26984732 cec3ae7bb7fbd3e5f736861b19d25ce9 Size/MD5: 258874 4bf1e2c311d88d8bc6383401bc21eeae Updated packages for Ubuntu 10.04: Source archives: Size/MD5: 127760 f0796b8d3dd80d8b718a54da515fad45 Size/MD5: 2468 0496451632d6a003dc9095db97c0d793 Size/MD5: 68315117 09ff345836841ae848e30da7ab089c87 Architecture independent packages: Size/MD5: 19756666 df5dd28892b48d1d50f1752d4af9d006 Size/MD5: 5906758 2e16cf33889ff6a36a4f6db1e2d70e1d Size/MD5: 26752410 2cdc21b553c1dbfa043475b446c184b3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 374844 e812f1588f4ae09c86ff035342fe8de9 Size/MD5: 84122 befffe844778347f9e51c6a5246286c9 Size/MD5: 104359132 d4af01ec34a7b642ac6524d25c676606 Size/MD5: 2362186 266e50ddbe51965c282069772cdaf8a1 Size/MD5: 11031928 822c455df48e523408f9af52b4d791dd Size/MD5: 25544484 55dcac76014a3bbab7a7efb54203e373 Size/MD5: 270830 26c15b2eced9b04aea9885d5d68ba687 Size/MD5: 2097278 8ee2ef63da23adb85de87bdef38db52d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 344476 ab2908e7ca4e1e43bfc52f3861e174c0 Size/MD5: 79580 a123eb5b3abcd954f5ea61e9c8402e3c Size/MD5: 168622120 743060d4250cdd47f6e76b327e126a5c Size/MD5: 2349246 d8eb8648ff1c693815f8d9daa1306528 Size/MD5: 11031048 b0ac93a9d17bfb0a5c496f7e400f2247 Size/MD5: 27281148 473b5a8db8af629f02a8e16cde2dc85a Size/MD5: 258628 7efd72b70b8c42ab62dfcdf9b3068894 Size/MD5: 1785514 e39574e157907db21fa81add56c4e5e6 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 364932 52e29432112bbf1fe30be0adf07fe63d Size/MD5: 83618 5e0d870ef45f9f1e71e36c1f1e5982c3 Size/MD5: 87238282 cd3b54a21720253f2cd400f092b28092 Size/MD5: 2364020 dba64850f3cb6002878db25883adebae Size/MD5: 8981780 deb382969d2227c3000b3910cb407103 Size/MD5: 23891416 03117ce768423524eeadb73823de10aa Size/MD5: 277906 248757af29f57c3bb5e9ea720bc47f71 Size/MD5: 1916212 0ed557c97781af64eaec545987722a4f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 77754 4e00d0b3675fb291e8ca43d9b4d9bc6d Size/MD5: 119494468 28ce4bf9f48b5d0c1aeba121d253e725 Size/MD5: 2363704 577737234ba4a2a85e9645730fcfb69b Size/MD5: 11053142 d91160d4031be58bffec957d0238859a Size/MD5: 26910294 9b944da4921b6b2596ccc67e618743c3 Size/MD5: 259328 09bb890995c372c9dee85c5d0a3e5774 . Remedial actions for vulnerabilities in IcedTea plugin on Ubuntu to safeguard user privacy on compromised systems..IcedTea Plugin, Ubuntu Security, Privacy Threat, OpenJDK, Software Fixes. . Severity: Important. LinuxSecurity.com Team
JunkBuster is vulnerable to a heap corruption vulnerability, and under certain configurations may allow an attacker to modify settings.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200504-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: JunkBuster: Multiple vulnerabilities Date: April 13, 2005 Bugs: #88537 ID: 200504-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= JunkBuster is vulnerable to a heap corruption vulnerability, and under certain configurations may allow an attacker to modify settings. Background ========= JunkBuster is a filtering HTTP proxy, designed to enhance privacy and remove unwanted content. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-proxy/junkbuster < 2.0.2-r3 > = 2.0.2-r3 Description ========== James Ranson reported a vulnerability when JunkBuster is configured to run in single-threaded mode, an attacker can modify the referrer setting by getting a victim to request a specially crafted URL. Tavis Ormandy of the Gentoo Linux Security Audit Team identified a heap corruption issue in the filtering of URLs. Impact ===== If JunkBuster has been configured to run in single-threaded mode, an attacker can disable or modify the filtering of Referrer: HTTP headers, potentially compromising the privacy of users. The heap corruption vulnerability could crash or disrupt the operation of the proxy, potentially executing arbitrary code. Workaround ========= There is no known workaround at thistime. Resolution ========= All JunkBuster users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-proxy/junkbuster-2.0.2-r3" Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200504-11 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.