Monday, November 11, 2013

[CentOS-announce] CEBA-2013:1511 CentOS 5 rgmanager Update

CentOS Errata and Bugfix Advisory 2013:1511

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1511.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
9ded8cda8eaac003ade6fe78617fb6adb8b0ab38a1e8195722f53a2422392b8f rgmanager-2.0.52-47.el5.centos.4.i386.rpm

x86_64:
737e69d1517b587c8a4f6bd8e67c22f49025864e305a1aa49030835d06d8d9d0 rgmanager-2.0.52-47.el5.centos.4.x86_64.rpm

Source:
ba0a1e6566686f8e71e6dd00e65bcc11d0400485a2da72cdf739c2e98b0811d5 rgmanager-2.0.52-47.el5.centos.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

Friday, November 8, 2013

[USN-2020-1] Linux kernel (Raring HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWbbAAoJEAUvNnAY1cPYI18P/ip4/de9hOfVSNJisrr1Dzp9
9QZNMpK1etrf/a79beyHYGyaR7tLZTLTunfNzIgsJJkxu6dYZV1BVeUbQ7dv/gzi
itIpRL3/VRWGKSdH3+k1PC3ntroS1yydoodtzELww1LpfP03burDiGD+ijkciokV
rdZWfz6Jh1KNUVOcAQLWJADiHvkXonNUSAj9MLGJuriXabBMjnl2aSTGtcYSBmA0
+AjT85D/HOhbN5lInf1/XAIvx3alrF0u4NK/lRgAByp2ludXWdxFW49McBCaRoHi
C3zs46vGbrLqlWieqgVE0W1sbmFc4xQmA/lP9eNyDm9xrhGrSfQf44FOtl0cMMsW
sesw+SOkelupD+GyoYfqXGLGpoYpbFPeF1YwOJaJFMJ+kIAQF16JELoaFpzItu7y
iPIg9MpiSdePfYivVVoFkQIo3luoODAcMfQbeCnsliox+587183Bh97MFNG6IquH
vqOKbjc4V00jDrs+d1CpZBdhXNd4Ev+xppMWeWT7EtX19v8IRBU7fInYdBBQz6q2
LUpOOcTf/AyDHz9YrPWYYgIUhxJo0VD5Mnnh46KHNghA25kVtA9DYoqBJhOWi+aZ
0WGK5klEM0zSQgl3gVQ2UhSRIvgo2e+8PPC/ftpZ5hACFzICflyYOG3BuskZtdAh
bwZlOWgCyzQZOPcJcVAb
=OT3m
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2020-1
November 08, 2013

linux-lts-raring vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-raring: Linux hardware enablement kernel from Raring

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

Dan Carpenter discovered an information leak in the HP Smart Aray and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel when CONFIG_HID_LENOVO_TPKBD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service via
a specially crafted device. (CVE-2013-2894)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Wannes Rombouts reported a vulnerability in the networking tuntap interface
of the Linux kernel. A local user with the CAP_NET_ADMIN capability could
leverage this flaw to gain full admin privileges. (CVE-2013-4343)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.8.0-33-generic 3.8.0-33.48~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2020-1
CVE-2013-0343, CVE-2013-2147, CVE-2013-2889, CVE-2013-2893,
CVE-2013-2894, CVE-2013-2895, CVE-2013-2897, CVE-2013-4343

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-33.48~precise1

[USN-2024-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWY2AAoJEAUvNnAY1cPYzFIP/AssooOed6F+on/1xp7SxED8
0bcMiCDaqmBBhkEwXxF2zH6114LVgTWkuYXpqd8m0stDnBmKavxtsVM0t6kjIWfh
zHGeWPOtolKfL5qAbsYX9pGNlNxIAjg9dk7o94Lxk0wF1+VMygsGgo3luATkNqxO
iczNQJQGyHZDJioaHffWFM4U19aoC22xrSlwl3wICej5Qu6wZtvXwO9ZDKlPm3FP
DH+nJIjV7iRuBgvOTItQoFN1fN2/eP3+E5hhbqVmUyXDkEmQDEsWSuezcd7hSCyF
ZW8VahjBokEKmEP8nErLDh2PXgjpeet8G4TLfbCQoDgneTHjS1ynAqZmse07iAIK
ok++Ls80TBaAvIvThFLyIGT4Ia0o4esuLepKFojMdSl+Oc/pJxR9+eZwRcmWaVsr
h2ofburQOtMzxnfi3OzGV/iN2wGogdkgPrnWMNAKRv1lmsgLl0BSp6r/ouYPUw3H
KXqkV+w85BgYNZivlf22h5RhuAcEeUz3TgJ2g89YKmgDlvLB79XuSpv/vdvPcFeb
wOqsil6fvbI6Zf/wpGq+I4NbLDEB6JSJqbPTOYin0To5OUHwhqLqzZdERsvxmu8D
4CcXg89F8Zmp2oVRzWRhmNJ9Lu4PaJf/dgcqXbCprt8AqKFxOS6BosuKztq+2FLK
+liVnzBntxkN08je+zWE
=55gc
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2024-1
November 08, 2013

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
linux-image-3.5.0-235-omap4 3.5.0-235.51

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2024-1
CVE-2013-0343, CVE-2013-2888, CVE-2013-2889, CVE-2013-2892,
CVE-2013-2893, CVE-2013-2895, CVE-2013-2896, CVE-2013-2897,
CVE-2013-2899, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-235.51

[USN-2023-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWXKAAoJEAUvNnAY1cPYvZAP/RPEwdsWCopfZB9tVifYLAXg
GOXqB/42dI5jDKP2xdflTRDlvYuIpzN965Fm1AM1uwCc3CC5I3aYaGWOU9RZSKkJ
n7y2qCRhN/Uk7rOJpfnvViIOAm2EiDY53zmU3MHu3slCrnU8UsfujnaerYTgzFEi
T/dt6O9zlS4qgNAP17ED7tuqUlk1PW2U+0M6U6+0YLPzbgMQy+zYJa2NQSeqvmP6
GFswctc4U/GrJ1kaZLZHrWYeUxMxWYdmqvU63fZnHk/yDOafDGO8kxHtp9YfKDFi
WXNzJllakC/Qmmmt5d4WDVTBpxh6h+KkYzsWrOtFz2GyHoaRm4pFqB9vn3ASjda3
eRmS4jVSr2HmyeTUCLEijhcF6WZIafMSqznwG1t1XK1jjNITrD1YYLLRJ2WVdoR/
ejXv5ngyGfWHbDwgyTJlVw6EEH9cARJ5K00R6jqh+o5pvS/zhVk4PJsWReezl/ZX
edEBU6dmvUjYng+JpwVGzxJYkpyLOnaKgJPe8hKopBuF6+N07fG9N5fE30wD8WiZ
DcylWwdZjlRTT5rETsLMzYDvybhu5ME9kweAXqpEe25RfsVhpH6lSWk1zeSVXVpm
DPINHnuXHIRdTEWgMqZvgp4QHH36UeTgJKRLtHb6tXMhXunHjy0rSimIjEGlLrXx
97Cn6Mu8BZfV6+CoLK89
=wwL3
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2023-1
November 08, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

Dan Carpenter discovered an information leak in the HP Smart Aray and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel when CONFIG_HID_LENOVO_TPKBD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service via
a specially crafted device. (CVE-2013-2894)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Wannes Rombouts reported a vulnerability in the networking tuntap interface
of the Linux kernel. A local user with the CAP_NET_ADMIN capability could
leverage this flaw to gain full admin privileges. (CVE-2013-4343)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
linux-image-3.8.0-33-generic 3.8.0-33.48

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2023-1
CVE-2013-0343, CVE-2013-2147, CVE-2013-2889, CVE-2013-2893,
CVE-2013-2894, CVE-2013-2895, CVE-2013-2897, CVE-2013-4343

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.8.0-33.48

[USN-2022-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWWmAAoJEAUvNnAY1cPYLxMP/0wJo3pmkvFlegYJ/fYkTxGe
79JO8LKpMpqhl3M/MXi4SuIlUFSd2hf9PFrE28+zFbOW/0RhIp3NPP3k9qIP09o/
LbEKxt+b67CTffCsr/5rJn7WVo8f3UKv6+q65lYdaKYc8+/xhh1O/unMZIguw5Ye
Wz7ytKYdnJslRKPQOAHbdP9JPLJm4SesgsehSVikV82xcOMHxUJqInbwDmV1/JO+
4GhyAdFiptUlIJbveS4mqxoXYBuqnFZUypuSf/t2elpYBEpz420TkY42dCnAVwvJ
c4qs1NDrdEIgREOtiaIZfHtL7QPqDBJqYrnXEDzdt5wWu8P5xzbrOluPZ+5Mqldt
EElGvPMDoLjs0L+kQ/c/o6w3AGrXnRhDriJsMBTVnLTPvHpmQMsGk7xq5cTyw2oq
tq29iDR2LCOR5HCro5IlpGCDlUViwEr1irsQ3wXdKHvtpCGCEHoAfbst76pf3YEu
DKWhiThtByjAFbpO2TzkYzDpX6EqYg89i6dDDO/EboHU/IijD2anFfqKEOEoXnfg
vGwmbn80OJIOp8u9Wqg5bnMPJtWOrgTHfur+Bd+bBzenW+svjUZHvOdX10WsTbd4
OgMyP/k+dpJidsAovcDuTeHDLVEZXinDQbHkRV4aHPAXPVD/NGeNBnK6fmLyDNdH
x4u1SVErrSamHw96QOou
=pM/6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2022-1
November 08, 2013

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
linux-image-3.5.0-235-omap4 3.5.0-235.51

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2022-1
CVE-2013-0343, CVE-2013-2888, CVE-2013-2889, CVE-2013-2892,
CVE-2013-2893, CVE-2013-2895, CVE-2013-2896, CVE-2013-2897,
CVE-2013-2899, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-235.51

[USN-2021-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWWMAAoJEAUvNnAY1cPYdAQP/27+HKzCRbepO4gz+8KMMSy/
qbKPlmw5VomeYdvq8CVXQjXnKpZehpgkxnv4ZiwVXA6rdho+NkbBYPlam7Blqp2m
gZtYKWg33yzRXt+qO3Swc0zkcQBOELJSeWhaGYRc4M0VLscY7H7aHivhm4546vOZ
0D3ylmZhzp2UUylszdOS/6uVHVUyX/i8QIMiPFUT+8GzjJJtQpZa9su6bq/8YGBt
2taKPf00bDYUmorJLG4hLE5dEgaCPzGJCS/qbUxQHPxgfpmy4bqSbkSgaEZroeaN
AoM9Iiz+ZDgXXQhrhmZc7HAmuexid+teTJyt9cEPJgsRiViKpggk70moxWRr4MXu
ZmoNFN6ODEDkKX/apEO09FGIw6z24UgEZO3AqVKvoOY2aKAq7ds7w7lt1JggaENr
HCFTn9PSeFN+hmRrtuRXWJKvI8/BWpl5Kl/deyNfhbkLVEJEZ29VOnAjdJxNiKu4
zD68DpyPEyVcboRAe78+MpZAbOTAFaFQr17h8DzKmEG20KWuZ9BWpmiIHQ5VBESw
kK5nGBpbCtdvehlBKE0ie43S43eEcphUol4IV1d3XjzGhRk0uvH+O+Zscwq6Em8d
+xNtsv69SdUAwfNWWe0WYmJFN/gNad3dnxWZxH6OPi3XeJCrbwChs5hWIWF8yFOC
xQUuQ10cVvbEBHEvZakH
=jurt
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2021-1
November 08, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
linux-image-3.5.0-43-generic 3.5.0-43.66
linux-image-3.5.0-43-highbank 3.5.0-43.66
linux-image-3.5.0-43-omap 3.5.0-43.66
linux-image-3.5.0-43-powerpc-smp 3.5.0-43.66
linux-image-3.5.0-43-powerpc64-smp 3.5.0-43.66

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2021-1
CVE-2013-0343, CVE-2013-2888, CVE-2013-2889, CVE-2013-2892,
CVE-2013-2893, CVE-2013-2895, CVE-2013-2896, CVE-2013-2897,
CVE-2013-2899, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.5.0-43.66

[USN-2019-1] Linux kernel (Quantal HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWVOAAoJEAUvNnAY1cPYw1YQAJWf9SN75guEoEiIMkuh0rM+
tQd1BfZBCoBk7F3KKvE/dXWwHJiLmEG99SMeFOTCT4IqNl2R99VfDDsFGQ9PQf7+
MlDVAD76Htyt9OOfcDUd0HETQ4Kylt1hOlqxhktUKBSlBEagfZ458LYYwtdD3MNh
pkZYCqBuhOwf1KysIUvA3RkQ4A3NwC/FyRiQPw1usOEBNqAATizCK5dzjiDQDeL8
1JL7D0GM2nn8EmuWmlJmzytEWV35DjEWLwlLt6CJlBUjlQZHCTOewQnwfkMU6Yow
zCqk1rNPFm3MNFxMnybnblRz2i3x4BTwljPt8NKtFdgdA4Svvp+O75yJdvzpvZIW
ogVdZNjEKhHywsgFk/PjXRMSf71LEwt1Bd/G5XLB5PnrjfThtYoEUY2sPTPAivJR
+IpVogGL6xQ4oywkA7pOKUOSJh5vbluSvsCwY11UTTmTZn0jtLZ+AGvaWSb2d4F+
Rrh/U5frOMaFLy+LNEXvIdIJ3SwmgLn1CCvkjubfILULGiUPOoWFA9YjpsbB2ZFj
JkQQfr67SiwUEVIGKXHHPE/C0LJEZG7GbvgUPxGwXrZ+EQ926uDyB1KLgTOMg0Xx
wOZhy+S2vBUBROVPNIwMoyaj3lue8L0HAEREkecpJgBb5HQfqGfYQ6U5EyXn+PM8
fxL/M3NOegyMRYH9cSNa
=lOC5
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2019-1
November 08, 2013

linux-lts-quantal vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-quantal: Linux hardware enablement kernel from Quantal

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.5.0-43-generic 3.5.0-43.66~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2019-1
CVE-2013-0343, CVE-2013-2888, CVE-2013-2889, CVE-2013-2892,
CVE-2013-2893, CVE-2013-2895, CVE-2013-2896, CVE-2013-2897,
CVE-2013-2899, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-43.66~precise1

[USN-2018-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWU2AAoJEAUvNnAY1cPYkpQQALnR2oNc0cJRGrGYvHGk0OKE
B5/BsioS4sx2n74UOnR6aJUeiOmF5kRdIPgLd2KU2EYjs4NN8ZeYZXfc/T5B8iBm
2XTQK/eRhoGg/FcZ/mZZK+DK4G0+XZL6bUWzWReHabZaeKMlVV5HaMIJl5bVvG3V
0A5Fqm71M0Sf3Aj+HVWlLp6eMjvmC06ZOptwhiFQYNLziZtoA7dKQNwi2FVoo5sk
B9sqaFbRpXixeCyHyWt5jRL5IfFCqLv7/XEqRcFMjQxAQKfwzi5KXkaGMdV+piOK
Pzbmr5g92HIE+L6I1Qjg+t7SBxl4+DoitWNShpfqcC+0Yz6EzydzRsfZUvfeCaU7
z41TjRE0BOue6nDUsOc+ZI3WiPo/m//3lKGK1rX214+F/CxZvS+1tQZ8zFQKEGPd
12jx6KkVdevmhRWGtOoerhDgfH84eDei3LTCalinZwAEMJIvRrZpP5Ml15XyaTMa
CN/afp6q9dB4pSN2YFbzS4srbamElCHJuL10mIYZ2hwNbgAv0eY6FjrMhRyAkxCO
m0G2Va7OBQ8/LB1t68fJCQ9hAgEY82LGBxTKv+rx7BmdXqU3+ABF7E99vqP0KeJF
1KOTncuwqhaxtO+uIxu2gfTcVTC1vQh3+NZgpmoIWEQa2pxbjlUaGrgrchTn5CI3
B+sXtThEvHnXo+FMAyCf
=IK2X
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2018-1
November 08, 2013

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)

A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)

Dan Carpenter discovered an information leak in the HP Smart Aray and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-1440-omap4 3.2.0-1440.59

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2018-1
CVE-2012-5374, CVE-2012-5375, CVE-2013-2147

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1440.59

[USN-2016-1] Linux kernel (EC2) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWUDAAoJEAUvNnAY1cPYrrkQALBw6cGdGEqFY0Y2cm4YZqJ9
PAYPCDn6Mc6BycxUsV9HMHTJI3HWyAyFkzZIDiC3GJwUMHhNJKNusKVUyPsDbxPa
VsdQjtWqwU6MIvWVSOYlFMhhZQixUxUZ3ZnktvDIJYQHGPbgNVyNYIY9vYHK09tm
f0uGKQZohB2zlRRw/sqDNwcEP5EYkjp7eMiVubwuyyiArIexbwnUbBu2quCfzTiT
a6yT9X7WMRQ3tEL/HIsC8oDz+HUAsE07iACSyb0duFZ1We2CyMN2JzM5aL4AbcRN
3zYe89eRYNAMv8jTHy+Xfbi36VcfkC/vMeFkzT6/jcAjmVwcw13FonXLWTfD9FAx
hKfmN6a54hj74cf6eoxGSBxq/yUY14m+ULw4NePL30mddYJePTNS/BOE4bq+RrD+
tnaup+coHfe7MRuEgZkjifqVdXtnfy+3uUQsuIvBYrTpaw2mc+owkKBicCVVFmO6
siKbGhxSMZ3WOBG3CoHQ0sIZ41EpBvKL7aT5eAqt8YI127DNWusGW5PiKT2SVNeT
zQS4Pr/L55bfxGOS4qeHjvG0lLic1HBwEBr5E740N8gZTD/sccM7ZQPYD5UoSUJD
rsAGR2aYPaPULXlb9yZqrUFTpWJ2FUKnlAdz5enua2OaDOgqo2wUwQ+3XE4NX/K8
cnqVJYjI/WYK18FX2gH7
=D0X7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2016-1
November 08, 2013

linux-ec2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ec2: Linux kernel for EC2

Details:

Dan Carpenter discovered an information leak in the HP Smart Aray and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-358-ec2 2.6.32-358.71

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2016-1
CVE-2013-2147, CVE-2013-2889, CVE-2013-2893, CVE-2013-2897,
CVE-2013-4299

Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-358.71

[USN-2017-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWUcAAoJEAUvNnAY1cPYGfwP/3tnxKcEmW7dGJn8YNjoPpT3
KwYAgJJL+Ax3u8zdqXJMUpQeJPmSz+5PgmPiJFMPO9YL/6ruG+VeGH1p1E5X71Vj
wmWqa8JKCORgJ0V6LXq/Xw4olsN1s854Y+FZrQHbRV6gwVmfKqfExeratIhPfsJc
FpGVshAPightUdB601kUqHFZWTWsDaeKhqZwSlW8USTOvMsrxFhAe29OeB8VNTSr
U8ULYybi6AMbfwRbOGqKwuhxJk0WCJ6BW0n8cB56tZyf1fajixsBTSzb5A/CvqGu
95mTnJ3W87vGOwumLYhUjnwEAFPHWgWLjBG+dgka9LPVqUXcRX9tyVTfpBQMXVRg
GlBdSOXLXG5MTU5GC0DgwFFiH0mXBaf4C/TV2o7aMdEbdl5RsXC9S/HDV3FsWWB5
bgRtE0XujKYXw3H5rCQZ8ZrEKViq0j5KXkGRAzDkz2UdBv4Bzct2Wx1yvO9Lfx0U
JR961k0aLUSHwG4gxcOqXNCFvomhs/pae1jCD3+YC87gP2FKKs/3XU7ydL8tIK0B
tdSjRjCRrK3HrTYrj49+WcyCOjiH8Euh1+2Ycbnihuw7vIXgkefoD1mrhd/4cSQi
J6pHkLz9WvbNX4lLE+fy1SmelAWKzirT48VtmHt5Xa6ziP/F/qEGOkGfD5UGt4Z1
VXK6OQ8+LseSwEK2evuz
=QoeB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2017-1
November 08, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)

A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)

Dan Carpenter discovered an information leak in the HP Smart Aray and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-56-generic 3.2.0-56.86
linux-image-3.2.0-56-generic-pae 3.2.0-56.86
linux-image-3.2.0-56-highbank 3.2.0-56.86
linux-image-3.2.0-56-omap 3.2.0-56.86
linux-image-3.2.0-56-powerpc-smp 3.2.0-56.86
linux-image-3.2.0-56-powerpc64-smp 3.2.0-56.86
linux-image-3.2.0-56-virtual 3.2.0-56.86

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2017-1
CVE-2012-5374, CVE-2012-5375, CVE-2013-2147

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-56.86

[USN-2015-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfWTgAAoJEAUvNnAY1cPYOeAQAJUNoWrUbLkUAHtUPWgcfhHv
L8F7j8XMoUfov6A5+fFrOiZKBmE42wwxLeLJWx8koRefGShEXNrNBsX568FrdCi/
QcQO4TqZcGYKFdwplhc4Zrn3doid7cfirsxKuHNKeMx2sd3I/mZprtqRZTcpnw84
BasSN279l/OYn/iU9VuXNWXhJmGedVMXrj7FWacjqw2rOXsXtx4NFTgVqgjRlzAY
U/LqPwgi7rNvPxTatpM5x3pYtKIa4fJ76ogZYcSdTLTbIeSez9vYuV96K9EUmOJF
CEt4veosxuDMHpo5ZtXMd65SxZ7lj5HH8GM5kufVufaidkZ4yYWrxS2ICcML5vr6
st2uX2nJiomaSaUEZVig4x0/NTyTOQS6TUyJ6jIcIo3TTQjcG92fMgpdtyHmWLjA
gOIUzdCpTSiw1z/wXPnSWIPpch1Bkvqmhmr+G/fe074izzNUF7Gh+j9VsAYI/6Mu
BM3B+Z6WZztOTKsmP/P5AEiCv5qjIsvzVsE3YNnUsWK7LuY1fLN+yN6UfFggCSjP
p3OKhEDaOyg1LFjZMVd75GSb4aqO1wkSqiSHGmygIYZ7AwpzghiZxpt1/bvvrUi/
+Lcxp7SiEkpUpaIRUOm8dPf764dsuISL1dM38lLB+sK/ZMbee9YTHLNlvaV3y/WB
TdnPM7UPamd3wfSfw6Ga
=McOB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2015-1
November 08, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Dan Carpenter discovered an information leak in the HP Smart Aray and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-53-386 2.6.32-53.115
linux-image-2.6.32-53-generic 2.6.32-53.115
linux-image-2.6.32-53-generic-pae 2.6.32-53.115
linux-image-2.6.32-53-ia64 2.6.32-53.115
linux-image-2.6.32-53-lpia 2.6.32-53.115
linux-image-2.6.32-53-powerpc 2.6.32-53.115
linux-image-2.6.32-53-powerpc-smp 2.6.32-53.115
linux-image-2.6.32-53-powerpc64-smp 2.6.32-53.115
linux-image-2.6.32-53-preempt 2.6.32-53.115
linux-image-2.6.32-53-server 2.6.32-53.115
linux-image-2.6.32-53-sparc64 2.6.32-53.115
linux-image-2.6.32-53-sparc64-smp 2.6.32-53.115
linux-image-2.6.32-53-versatile 2.6.32-53.115
linux-image-2.6.32-53-virtual 2.6.32-53.115

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2015-1
CVE-2013-2147, CVE-2013-2889, CVE-2013-2893, CVE-2013-2897,
CVE-2013-4299

Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-53.115

[USN-2014-1] OpenSSH vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSfPrqAAoJEGVp2FWnRL6TrKMP/3oO63qR3elAj8jUVO92kYiQ
K5wq483/os6q98rafRDTeZzq+ERkPSEsBhUpU5JQsNSMsAtQmcncjBZJkr96s8yY
U0Y6Ia7APRB7VmT5cPBdd4t5T8ams5tEkq0edzOQ0CXWQSBeVJc9xGKiKUzLogJE
yeCv6LtoYF9FwUfkBAuRHVAW44VCDmH0X0ptippq6MuEoIzqe3iPSm8P3fNiT3+Q
KoBV5tvAmM90MTcugMo62SoB1cDM1eFYPVgoQ8zSnxDvzMyN/LmlTLi211vI9eh/
7o3haXG5ikSZV8s0S94XaRX9CyvMAKYzo8hIRE3FTe9ONm7s8+XxvyUXrJKH41p8
nuGhF3Q4vxhMvfDAeVRSSgsezYmpizCS6566DndR5RGBdLHP/i6R4EVZ8VLZstLw
ibU+5+YTH9auEptGBwlaqUekSHJTIB+rKU0QYramKYz6KYRkUrx2R9rIu9pcpYQP
SeQIwc2YRwIMUd00OTxUFISLfHg/tf8qZG5NZ6EvyMrIk34lQuiIHORYvTfvr/nt
Q9oc2PXgLO2hWqwtGC3mBSiWJZZk+mencioEzx6LbBocW0O7glvByn8Uj1MIrKSZ
JddeFb2qCGbf6WCdzI+2a/3XVwStrPxMfLGfPDkbSOIJrrhzQQBfI1BYFziDzX5Q
/hi/qAN/p5fv1b30aY7h
=06PI
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2014-1
November 08, 2013

openssh vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.10

Summary:

OpenSSH could be made to run programs if it received specially crafted
network traffic from an authenticated user.

Software Description:
- openssh: secure shell (SSH) client, for secure access to remote machines

Details:

Markus Friedl discovered that OpenSSH incorrectly handled memory when the
AES-GCM cipher was used. A remote authenticated attacker could use this
issue to execute arbitrary code as their user, possibly bypassing
shell or command restrictions.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
openssh-server 1:6.2p2-6ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2014-1
CVE-2013-4548

Package Information:
https://launchpad.net/ubuntu/+source/openssh/1:6.2p2-6ubuntu0.1