Monday, May 5, 2014

[USN-2197-1] Linux kernel (EC2) vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJTaE2CAAoJEAUvNnAY1cPYexUP/0xiI5qQF0zNBoXEGC4az/bk
yDc5LkE2Tb1rkmYzeuidgcxOsMKCUn6Fk9m13VSeol2xsd4mQQncH5SysJBpgpqB
+oH/ECqhMPXMlAXuO6myTswOSbEtv+0lRh4oBpK7bxC0Xi2LFLh/gA/xBFvypn3s
bsL29RwkeqMCJrp24sel87ZYriMFhA/2jjAJ8WHSIRMmy96QElPGHsQSrQJZNLTN
iLYb0qF+tggESDjMwGjQ53sXb02EYUYL7NLo7UdsW97TDXDKAFMWHTj44Fd7AfdU
SMeEcHvIx+8aJfOb+UHcy/fHXKcGqU8Of/Sa3eZRYo1tprC10vSkUhRxQmjHpyTL
m7ROrmrwI1mfwTB9itfkLxyhrdc7fBr/rYU62Rs7lPr4sbMIb20sOrdA1F0bJp4X
pl8HXiBMEhfqLfthhiMmoOVGxHLrMl3VG0r0x6irKwvlComGhRlLF3sa/9q17NzD
RPnsrJuIv6Co9dU1diu+/7kMuHO7QvK0aheA6d2+bTtKY8liuinvm8Y67ti+6/r9
oBSa5UsaUfTkFZltK+Ls6fb0SDqXsobCwVZsTTJAoFnBCzxk1QN3QCKIfeSOkeow
uVUXb61FHGs8YqqFuVJoj23KYavHX1yb06B1hEj0RhTKF3Cpc9ZksPreC8FTaqys
HgyU7xZuuJ4HKSgB4Xlb
=Xi1J
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2197-1
May 06, 2014

linux-ec2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

The system could be made to crash or run programs as an administrator.

Software Description:
- linux-ec2: Linux kernel for EC2

Details:

A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An
unprivileged user could exploit this flaw to cause a denial of service
(system crash) or potentially gain administrator privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-363-ec2 2.6.32-363.77

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2197-1
CVE-2014-0196

Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-363.77

No comments:

Post a Comment