Wednesday, February 1, 2017

[USN-3186-1] iucode-tool vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJYkjITAAoJEGVp2FWnRL6TjhAP/3X7MihuZjNybnRmvdYTVWMY
NumODA/ohBPZO+AMO4Kt1SqQWMNbzfSVXlJOx6HJM7nloVfbgJI1ZTc2vK6QgQCp
vR8LruPkqaF1gnAAEr1Vv2l0aGoGAnhFrtpeuYfv2HS2E+bWgo4H9wdDCK9zWOCg
44QibM1jiIj6IgXasc0auNwwbWEOyN+yqmzfPEYxZC1sDkR4u/loNXcquVEbtw+D
rKNK0xPb/gEbPiZOy6ztLSVN0Twf42sN8XQ46tPJpCRLsWY+ZihZ3Ujinl7MrS6/
np3ROjwa5hvqWQsj/YSMiw9ECu1+hMddde1hZ/Bfq6J3fWaZIJbZnBj1v4yFbA6v
AaEOhIfh5dNV1VGar+IkGEzUYQI2vdREiXQFqXTkUU2yfP4H61vQdzqhLkeWRnE1
CwwNSGIRnIiDcLKNcNRxAD21JbUo1eP30ryy/GA/ICSsYHA/El6AYAWKU8Tc5ohc
rW1VQhhpgoQjRtJiF7pIqzl+cZljfpcEaPTZQfUvy8wL+LU9nn3Kxxgu1Dr3+2DF
H/RN3vRHOexvuDiuK1l2MxaWUowE3SAFvUL7hUIexUZcloT3zdz+et6GO2/dzG9t
47QLYcZb0mOuz44JycT3CSVOxpewCw4Lcs3mcXVbjnYOnVH5fmUyhzJkDQUq5YP+
+6ZlmGiDLWYOthu8wkk+
=+EUF
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3186-1
February 01, 2017

iucode-tool vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS

Summary:

iucode-tool could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- iucode-tool: Intel processor microcode tool

Details:

It was discovered that iucode-tool incorrectly handled certain microcodes
when using the -tr loader. If a user were tricked into processing a
specially crafted microcode, a remote attacker could use this issue to
cause iucode-tool to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
iucode-tool 1.6.1-1ubuntu0.1

Ubuntu 16.04 LTS:
iucode-tool 1.5.1-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3186-1
CVE-2017-0357

Package Information:
https://launchpad.net/ubuntu/+source/iucode-tool/1.6.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/iucode-tool/1.5.1-1ubuntu0.1

No comments:

Post a Comment