| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.70971 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu USN-1244-1 (linux-image-2.6.35-903-omap4) |
| Summary: | Ubuntu USN-1244-1 (linux-image-2.6.35-903-omap4) |
| Description: | The remote host is missing an update to linux-image-2.6.35-903-omap4 announced via advisory USN-1244-1. Details: Dan Rosenberg discovered that the Linux kernel X.25 implementation incorrectly parsed facilities. A remote attacker could exploit this to crash the kernel, leading to a denial of service. (CVE-2010-3873) Andrea Righi discovered a race condition in the KSM memory merging support. If KSM was being used, a local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-2183) Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly handled unlock requests. A local attacker could exploit this to cause a denial of service. (CVE-2011-2491) Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2494) Vasiliy Kulikov discovered that /proc/PID/io did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2495) It was discovered that the wireless stack incorrectly verified SSID lengths. A local attacker could exploit this to cause a denial of service or gain root privileges. (CVE-2011-2517) It was discovered that the EXT4 filesystem contained multiple off-by-one flaws. A local attacker could exploit this to crash the system, leading to a denial of service. (CVE-2011-2695) Christian Ohm discovered that the perf command looks for configuration files in the current directory. If a privileged user were tricked into running perf in a directory containing a malicious configuration file, an attacker could run arbitrary commands and possibly gain privileges. (CVE-2011-2905) Vasiliy Kulikov discovered that the Comedi driver did not correctly clear memory. A local attacker could exploit this to read kernel stack memory, leading to a loss of privacy. (CVE-2011-2909) Yogesh Sharma discovered that CIFS did not correctly handle UNCs that had no prefixpaths. A local attacker with access to a CIFS partition could exploit this to crash the system, leading to a denial of service. (CVE-2011-3363) Solution: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: linux-image-2.6.35-903-omap4 2.6.35-903.26 http://www.securityspace.com/smysecure/catid.html?in=USN-1244-1 |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-3873 http://www.spinics.net/lists/netdev/msg145786.html http://www.spinics.net/lists/netdev/msg145873.html http://openwall.com/lists/oss-security/2010/11/03/2 http://openwall.com/lists/oss-security/2010/11/04/3 Debian Security Information: DSA-2126 (Google Search) http://www.debian.org/security/2010/dsa-2126 http://www.mandriva.com/security/advisories?name=MDVSA-2011:029 SuSE Security Announcement: SUSE-SA:2011:008 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2011-02/msg00002.html http://secunia.com/advisories/43291 http://www.vupen.com/english/advisories/2011/0375 Common Vulnerability Exposure (CVE) ID: CVE-2011-2183 http://www.openwall.com/lists/oss-security/2011/06/06/1 Common Vulnerability Exposure (CVE) ID: CVE-2011-2491 Common Vulnerability Exposure (CVE) ID: CVE-2011-2494 http://www.openwall.com/lists/oss-security/2011/06/27/1 http://secunia.com/advisories/48898 Common Vulnerability Exposure (CVE) ID: CVE-2011-2495 Common Vulnerability Exposure (CVE) ID: CVE-2011-2517 http://www.openwall.com/lists/oss-security/2011/07/01/4 Common Vulnerability Exposure (CVE) ID: CVE-2011-2695 http://www.spinics.net/lists/linux-ext4/msg25697.html http://www.openwall.com/lists/oss-security/2011/07/15/7 http://www.openwall.com/lists/oss-security/2011/07/15/8 http://secunia.com/advisories/45193 Common Vulnerability Exposure (CVE) ID: CVE-2011-2905 Common Vulnerability Exposure (CVE) ID: CVE-2011-2909 Common Vulnerability Exposure (CVE) ID: CVE-2011-3363 http://www.openwall.com/lists/oss-security/2011/09/14/12 |
| Copyright | Copyright (c) 2012 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|