Monday, March 24, 2014

[USN-2153-1] initramfs-tools vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJTMIh1AAoJEGVp2FWnRL6Tr/UP/RXDpwIQU65soKcO13dn+4ra
dJZFj3oUv6F6e8hr+CGYYE3j9rHzTNMr8YeZfQOxZwrLmnOjE459yAfgwObMceQ5
NtgsojIA0rteBQS2Lz23qk30gQw+bk90pGE2sPmcKgQpCI/KKTEKAg/bZ8RZUr0/
rx5XCDHhL5dbtHcHjZguWSXbb00exrKhC9di/YvWAD8vwVXpvk2zZts8h5Q9qLOZ
ZKCGvR2HprIhD9kP/L366VfMrwwkBW12qvq3ki9bOkNtk2CtzzwY/btz5kxRNPo3
BaM0pL+c82dKFeAtNo/KW5oO1bdOMYseV36p+UfH4TKBQhkb6o7qjJ4YwzDwdQfH
BNL/KIv0S5C40nVnme46EeV2Ya9LawfXxVX44AMqN7SSm6eltdgLo7qckcel/BNn
BVzc6o+R5Whz6OJkllaA0rRBVLMJ6yadwtLBnp5LdBIENIUPBE4Vptw8lLImcu3+
BX0aBRsrU8LFWG8I/qpXCR7t5huYQpoja5qemDk26j0D7gDALI/S1w2IUTUZCHVn
W63WMEZyoGqU/wsOg04mLhnOn9GvwBjP38CY2AIWAnOLcdFLU/MnyIrFnbq24Zna
wGHNNf0InQ56ABMXQbfGyvpzSoRoBkYKB3tJPwvwvpxioo2+RbUfaYMbTMiXVn0l
Fb3c6J69d2N5gjG0AQ4g
=DX70
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2153-1
March 24, 2014

initramfs-tools vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

initramfs-tools used incorrect mount options.

Software Description:
- initramfs-tools: tools for generating an initramfs

Details:

Kees Cook discovered that initramfs-tools incorrectly mounted /run without
the noexec option, contrary to expected behaviour.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
initramfs-tools 0.103ubuntu0.2.2

Ubuntu 12.04 LTS:
initramfs-tools 0.99ubuntu13.5

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2153-1
https://launchpad.net/bugs/1152744

Package Information:
https://launchpad.net/ubuntu/+source/initramfs-tools/0.103ubuntu0.2.2
https://launchpad.net/ubuntu/+source/initramfs-tools/0.99ubuntu13.5

No comments:

Post a Comment