-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpyUAAoJEAUvNnAY1cPYtoUQALXdHW2Y8Rs475Il4dOed79N
ypqP0mCDP8idyFM7ETYwTGmsPc+k7mrLzFGmCkvZvYTAn6iwLx+WHP/TENfROJcG
j+bsXL2BsqlYyK18CpsIVWe1j5WhWP6vjyQm6x3hPQVZPVwW0FZFdc/NeuTDX8TU
TMjP26Dnznu64CmxUkzj3cwBHGfta4d1wA+3KXqlVnzTgKaE0YV5jmzZSIgg1U6i
48fO19UQNhz05TRlvf70SsH+p74a7hK5VMCBhf53cSw2811L+Zfv4mzWTR/x/Cfo
Nys8wFeCH0xsfSc0w2uG0WSbw1dXreJCWWie8S03V3WM8RT4VY23DmtEODKplwCU
BojAeXZZXq86BGmU+MIu7IciImy5U4lYbWzRCCZuTE3bMLzX8mstHWgzfbu01WlJ
9/ksZomkG7ods/nRs5jU/HbXqnAz0X8WKwxQk64rQEkQGy+V2pmS+cu2EPOGo+y0
gBntU9ZTaI861sdZfoePWKf9F28jpvDaiDXxQ1W3Zv3x99PQtd0Qwr40omFplKgm
190hHMvg5yLo9LduXkac/2drnhzS86ZBqskNbThNu6m+66R5CJxK2icY81Fjyvn9
q/nvnksSBlRrtv39mQpaUTL0MqKI7Zrwsw7zY4ueo5bXOAZb1EGFr33Gmji9L+x6
R/oj5yOpkXiz5C7ahRcX
=TCt/
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2072-1
January 03, 2014
linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
linux-image-3.5.0-237-omap4 3.5.0-237.53
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2072-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-237.53
Friday, January 3, 2014
[USN-2071-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpxyAAoJEAUvNnAY1cPY8t0QAJ/1+JFBk5MCL7yQXgqYou+/
0Wi68d1KR/qjz5IEY0RMQFcZmMz1q8zuSOp9vSbCzLy+PTH8De5q7pppcywasZ6b
Ji/65LJD4hrmmESlR9+tu/jppab0RVU7pgTIR82kwf7tNuu9rzcGxx//TzHHxcdv
QlXh/Czgh1L6v9c7m6TMkGd17aIJE+lzZfHSm5YH08ce8vIN3NV7tcbq1pU1XObO
JAqJQ5FlMCIjdPa59juxb52CKVlexmVZKnwf5VUNcoZ7mGzlYpE59ELUOuRnJMRq
SCuW+i8Ns6O9a/BnOs2RYRsCNYTjUTeN2PdejApsloih+JtKyjpUPRFZZUTRBI2r
3djlN8SiRNxDgdzqX7Sv2Qu5KYX+q+UquUGyOo+XP+Eli23z1ta/RPdyhEpEge02
xGggEscrIOV9WVgPQsLHiPi3ntVGuBvZCn6NN6Z4FleURVqN0nUi4BSZLJ9rLJvL
rAQBUEWHqPn480ZtPEV3QUi1AnscyhyOVqenmgXLk9DI6L+issBIv6ymG/Xyeup8
EE13F6w8Ka0pU49gcz8g0BxEYEZD8Dpb78WWSx+U1I/Lfsi3HAUTfqElpdEUK5v8
1Lm/gff991ITdcLuR9eGvpNwMCvv1PDdrbnJ5fg3z1QWMTg1YJJLBaoCnEV7vMvl
nxh0Ym7XDKBRo+/W/1g4
=Wa2p
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2071-1
January 03, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
linux-image-3.5.0-45-generic 3.5.0-45.68
linux-image-3.5.0-45-highbank 3.5.0-45.68
linux-image-3.5.0-45-omap 3.5.0-45.68
linux-image-3.5.0-45-powerpc-smp 3.5.0-45.68
linux-image-3.5.0-45-powerpc64-smp 3.5.0-45.68
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2071-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpxyAAoJEAUvNnAY1cPY8t0QAJ/1+JFBk5MCL7yQXgqYou+/
0Wi68d1KR/qjz5IEY0RMQFcZmMz1q8zuSOp9vSbCzLy+PTH8De5q7pppcywasZ6b
Ji/65LJD4hrmmESlR9+tu/jppab0RVU7pgTIR82kwf7tNuu9rzcGxx//TzHHxcdv
QlXh/Czgh1L6v9c7m6TMkGd17aIJE+lzZfHSm5YH08ce8vIN3NV7tcbq1pU1XObO
JAqJQ5FlMCIjdPa59juxb52CKVlexmVZKnwf5VUNcoZ7mGzlYpE59ELUOuRnJMRq
SCuW+i8Ns6O9a/BnOs2RYRsCNYTjUTeN2PdejApsloih+JtKyjpUPRFZZUTRBI2r
3djlN8SiRNxDgdzqX7Sv2Qu5KYX+q+UquUGyOo+XP+Eli23z1ta/RPdyhEpEge02
xGggEscrIOV9WVgPQsLHiPi3ntVGuBvZCn6NN6Z4FleURVqN0nUi4BSZLJ9rLJvL
rAQBUEWHqPn480ZtPEV3QUi1AnscyhyOVqenmgXLk9DI6L+issBIv6ymG/Xyeup8
EE13F6w8Ka0pU49gcz8g0BxEYEZD8Dpb78WWSx+U1I/Lfsi3HAUTfqElpdEUK5v8
1Lm/gff991ITdcLuR9eGvpNwMCvv1PDdrbnJ5fg3z1QWMTg1YJJLBaoCnEV7vMvl
nxh0Ym7XDKBRo+/W/1g4
=Wa2p
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2071-1
January 03, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
linux-image-3.5.0-45-generic 3.5.0-45.68
linux-image-3.5.0-45-highbank 3.5.0-45.68
linux-image-3.5.0-45-omap 3.5.0-45.68
linux-image-3.5.0-45-powerpc-smp 3.5.0-45.68
linux-image-3.5.0-45-powerpc64-smp 3.5.0-45.68
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2071-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.5.0-45.68
[USN-2070-1] Linux kernel (Saucy HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpxUAAoJEAUvNnAY1cPYUfMP/RyjMo9R8LW7syfJRYtmZoGU
57hRi2XNdFhv33XDaCFgWMJc9IkidRwxzGgojOUsk3ZAe/OlaHL4kfMYhRCCoyw6
yx5PS5x0eZFIFA/g23XVhvjt8lbSDltFaJA8VjHzmP5CAs7S5m7nDv1nBSZPr4eH
01K9u293CR4/dDRGXb4Q2VwBN11vdxXHAwA1/LwtGfEQbnh/ORm1msFsfB/u6ovL
n+hyXTMMQeXFZwt9RQw77bnJ+a9zlM6QCxYnt+Kja/s8G8K7apdV0cBqzMroEWt/
oadho+1vNprWql8c7yqs7nzfOrYgtMGwmz0QBVwGgPAZyVjTnolQg3zeqBbqYOdJ
s0CsZsUfyTfvxBc2AMyVLwH02VygV0yIiNPOwNHCHKtXmsrAGypjlcwJSSSLL94c
ZHTavdl+FPuTwV2uWRzD5/98KHOvXVMbQ1WmnMffvr0R2+rupotgDT4/7u1vNbzL
ZKp5M3PnoZMun42gzpgMWaS/tHEIn7wr9usYkxukMQxTmU9OxhTdsbuSVvIArRc9
psqjiTp1yhlCFb8qr+6aBt4/ux72kpU0Wu0kH6vg+DFb2c2o4dPLY5wDw73epsnf
LWpuQmXP8t2gHZ7TPWzPj67bjq4UBS+j3VwPjPcS9UL6Nln+VrY/ExkhzsnId0/6
f3/j8fcNbFuBKJ2Hs9hb
=AHed
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2070-1
January 03, 2014
linux-lts-saucy vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-saucy: Linux hardware enablement kernel from Saucy
Details:
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for the SystemBase Multi-2/PCI serial card. An unprivileged user
could obtain sensitive information from kernel memory. (CVE-2013-4516)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec
AACRAID scsi raid devices in the Linux kernel. A local user could use this
flaw to cause a denial of service or possibly other unspecified impact.
(CVE-2013-6380)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
A race condition flaw was discovered in the Linux kernel's ipc shared
memory implimentation. A local user could exploit this flaw to cause a
denial of service (system crash) or possibly have unspecied other impacts.
(CVE-2013-7026)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.11.0-15-generic 3.11.0-15.23~precise1
linux-image-3.11.0-15-generic-lpae 3.11.0-15.23~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2070-1
CVE-2013-2929, CVE-2013-2930, CVE-2013-4345, CVE-2013-4348,
CVE-2013-4511, CVE-2013-4513, CVE-2013-4514, CVE-2013-4515,
CVE-2013-4516, CVE-2013-6378, CVE-2013-6380, CVE-2013-6383,
CVE-2013-6763, CVE-2013-7026
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-15.23~precise1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpxUAAoJEAUvNnAY1cPYUfMP/RyjMo9R8LW7syfJRYtmZoGU
57hRi2XNdFhv33XDaCFgWMJc9IkidRwxzGgojOUsk3ZAe/OlaHL4kfMYhRCCoyw6
yx5PS5x0eZFIFA/g23XVhvjt8lbSDltFaJA8VjHzmP5CAs7S5m7nDv1nBSZPr4eH
01K9u293CR4/dDRGXb4Q2VwBN11vdxXHAwA1/LwtGfEQbnh/ORm1msFsfB/u6ovL
n+hyXTMMQeXFZwt9RQw77bnJ+a9zlM6QCxYnt+Kja/s8G8K7apdV0cBqzMroEWt/
oadho+1vNprWql8c7yqs7nzfOrYgtMGwmz0QBVwGgPAZyVjTnolQg3zeqBbqYOdJ
s0CsZsUfyTfvxBc2AMyVLwH02VygV0yIiNPOwNHCHKtXmsrAGypjlcwJSSSLL94c
ZHTavdl+FPuTwV2uWRzD5/98KHOvXVMbQ1WmnMffvr0R2+rupotgDT4/7u1vNbzL
ZKp5M3PnoZMun42gzpgMWaS/tHEIn7wr9usYkxukMQxTmU9OxhTdsbuSVvIArRc9
psqjiTp1yhlCFb8qr+6aBt4/ux72kpU0Wu0kH6vg+DFb2c2o4dPLY5wDw73epsnf
LWpuQmXP8t2gHZ7TPWzPj67bjq4UBS+j3VwPjPcS9UL6Nln+VrY/ExkhzsnId0/6
f3/j8fcNbFuBKJ2Hs9hb
=AHed
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2070-1
January 03, 2014
linux-lts-saucy vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-saucy: Linux hardware enablement kernel from Saucy
Details:
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for the SystemBase Multi-2/PCI serial card. An unprivileged user
could obtain sensitive information from kernel memory. (CVE-2013-4516)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec
AACRAID scsi raid devices in the Linux kernel. A local user could use this
flaw to cause a denial of service or possibly other unspecified impact.
(CVE-2013-6380)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
A race condition flaw was discovered in the Linux kernel's ipc shared
memory implimentation. A local user could exploit this flaw to cause a
denial of service (system crash) or possibly have unspecied other impacts.
(CVE-2013-7026)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.11.0-15-generic 3.11.0-15.23~precise1
linux-image-3.11.0-15-generic-lpae 3.11.0-15.23~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2070-1
CVE-2013-2929, CVE-2013-2930, CVE-2013-4345, CVE-2013-4348,
CVE-2013-4511, CVE-2013-4513, CVE-2013-4514, CVE-2013-4515,
CVE-2013-4516, CVE-2013-6378, CVE-2013-6380, CVE-2013-6383,
CVE-2013-6763, CVE-2013-7026
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-15.23~precise1
[USN-2069-1] Linux kernel (Raring HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpw3AAoJEAUvNnAY1cPY32cQALnkfTl+B7gY9Lxbld5ou25L
Bi6oHpXEuwkZIcnM2VRuEW5iUvCMmfGgQpQgNAKy9q890rgIID+Xv8trr7cMcBlO
nrwwNIGBlKhS9DqZLwoI52y7g22JrnCRA8ps4fEJ2c6tqp1EmAtHPXg1QomHQryw
SE/yTVOe60PdER1VqJX4JaL7R0sWV+pqbwCABP7zzFjIFcWjqmY7qpd8bpILhrpG
DsMwqhPy+Msy3rXcupCRunYMxMOWbq3XHmdjANgE43PbC/UHkd8h5xbtC2ZNNADi
Bw+p6jd6N0KdySPrw7Pw1oxwTZnk4fD0S+wp6VXydxkRhC9drLpEg45AULI9Xw1Q
WtJb51JCz8lOBY7B98lqZbc1W09fH261Lg+MMmN9TtvLoO0VhEqNUhJQQXeqTsY4
B2xYIIhYQoyWgzNVIXSV2Ym4nTcMCdPuRcZ6iE4wn8Wj1V3oJnXon0QdBDyxG3pA
7PAGEHIofj8OfpPWKzlmBPv30IzjXL+A/PDAT0aHPEaeWu5ePZM19cu2NPiluYkJ
XXfgniSZfHocLRXsHqXZmlhaWjJvLEwRhQBTibNGFOHiJ877bSUVQgbpq4ms41Ih
6kYVQtJPQk4coBQD9No+syWVxxSQ4XVfJV+O5OfYwyeN/9ocK0mRpIhASY8bWXpe
PrTnqJvaBCfz7MRYQGwi
=W+3F
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2069-1
January 03, 2014
linux-lts-raring vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-raring: Linux hardware enablement kernel from Raring
Details:
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for the SystemBase Multi-2/PCI serial card. An unprivileged user
could obtain sensitive information from kernel memory. (CVE-2013-4516)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.8.0-35-generic 3.8.0-35.50~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2069-1
CVE-2013-4470, CVE-2013-4511, CVE-2013-4513, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4516, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-35.50~precise1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpw3AAoJEAUvNnAY1cPY32cQALnkfTl+B7gY9Lxbld5ou25L
Bi6oHpXEuwkZIcnM2VRuEW5iUvCMmfGgQpQgNAKy9q890rgIID+Xv8trr7cMcBlO
nrwwNIGBlKhS9DqZLwoI52y7g22JrnCRA8ps4fEJ2c6tqp1EmAtHPXg1QomHQryw
SE/yTVOe60PdER1VqJX4JaL7R0sWV+pqbwCABP7zzFjIFcWjqmY7qpd8bpILhrpG
DsMwqhPy+Msy3rXcupCRunYMxMOWbq3XHmdjANgE43PbC/UHkd8h5xbtC2ZNNADi
Bw+p6jd6N0KdySPrw7Pw1oxwTZnk4fD0S+wp6VXydxkRhC9drLpEg45AULI9Xw1Q
WtJb51JCz8lOBY7B98lqZbc1W09fH261Lg+MMmN9TtvLoO0VhEqNUhJQQXeqTsY4
B2xYIIhYQoyWgzNVIXSV2Ym4nTcMCdPuRcZ6iE4wn8Wj1V3oJnXon0QdBDyxG3pA
7PAGEHIofj8OfpPWKzlmBPv30IzjXL+A/PDAT0aHPEaeWu5ePZM19cu2NPiluYkJ
XXfgniSZfHocLRXsHqXZmlhaWjJvLEwRhQBTibNGFOHiJ877bSUVQgbpq4ms41Ih
6kYVQtJPQk4coBQD9No+syWVxxSQ4XVfJV+O5OfYwyeN/9ocK0mRpIhASY8bWXpe
PrTnqJvaBCfz7MRYQGwi
=W+3F
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2069-1
January 03, 2014
linux-lts-raring vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-raring: Linux hardware enablement kernel from Raring
Details:
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for the SystemBase Multi-2/PCI serial card. An unprivileged user
could obtain sensitive information from kernel memory. (CVE-2013-4516)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.8.0-35-generic 3.8.0-35.50~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2069-1
CVE-2013-4470, CVE-2013-4511, CVE-2013-4513, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4516, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-35.50~precise1
[USN-2067-1] Linux kernel (OMAP4) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpv5AAoJEAUvNnAY1cPYDMgQAKaOfeGWI/oz0Uk0IALj4rvr
Bs/+Z7kDRo4T4CWFnQ9uJebNwRs68g4Wle+lyJ3yLmm+OGgfSOE45Tp/ccXxYqts
t34JXSuKKz9cIfNkyoPwLTmC/j0bsLWFjA/7kuT5AoGKrN7sIbAiICOM4zMQwIzj
UyTa5BLhHtxfNVVD/OMZEybjmRgaabkFyhf9ncADKgdEKvbsZ5i2iGDnOVspWzbe
MkB+TIUTnDTqzIKwePysowTKiGPZa3LOPRhE5F6vF0LdhuQmYNjnkx4eMbwIvfRb
/SkdqFzc+4TuLnEnNyQvzy2zqCd9bGyFQ80EjD8kIXwvPxfhRIFW0qc4UTVeuTjf
rWNhnyp90pqq9S9eIj8+wnus7u1DzA7Hyqy7AkWDqNoJ7jNnvsy7vXcsF04ELg3f
3A0vRqQwUFSgwhieYHCmuACGQ27hgrxTcJiMJ+gXK8F8cTz/yczqlUrDWg2sWpWG
38dTYOFcudziuUaQ9hz4yoTPl3o+GScCAf/OoB9iQjT+hlbmhpqGl0towruPXbo1
MbBco8Ttvuv8o6TPbsJzu2yuyxZsiMFJOJHTALSZcs9ohD6AWqnFP2ogcoUAxgXB
q2NoMzg5pUrVa3el5jVJQ2cXZ3oJJuU6FlGiWOuzgHMe+mi8A92H6LLvjfXxm9tN
j2SV3vSlgaiRi40wqr0Y
=cnAF
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2067-1
January 03, 2014
linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Catalin Marinas reported a flaw in the get_user and put_user API functions
in the Linux kernel on ARM platforms. An unprivileged local user could
exploit this flaw to gain administrator privileges. (CVE-2013-6282)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-1442-omap4 3.2.0-1442.61
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2067-1
CVE-2013-4299, CVE-2013-4470, CVE-2013-4511, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4592, CVE-2013-6282, CVE-2013-6378,
CVE-2013-6383, CVE-2013-6763, CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1442.61
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpv5AAoJEAUvNnAY1cPYDMgQAKaOfeGWI/oz0Uk0IALj4rvr
Bs/+Z7kDRo4T4CWFnQ9uJebNwRs68g4Wle+lyJ3yLmm+OGgfSOE45Tp/ccXxYqts
t34JXSuKKz9cIfNkyoPwLTmC/j0bsLWFjA/7kuT5AoGKrN7sIbAiICOM4zMQwIzj
UyTa5BLhHtxfNVVD/OMZEybjmRgaabkFyhf9ncADKgdEKvbsZ5i2iGDnOVspWzbe
MkB+TIUTnDTqzIKwePysowTKiGPZa3LOPRhE5F6vF0LdhuQmYNjnkx4eMbwIvfRb
/SkdqFzc+4TuLnEnNyQvzy2zqCd9bGyFQ80EjD8kIXwvPxfhRIFW0qc4UTVeuTjf
rWNhnyp90pqq9S9eIj8+wnus7u1DzA7Hyqy7AkWDqNoJ7jNnvsy7vXcsF04ELg3f
3A0vRqQwUFSgwhieYHCmuACGQ27hgrxTcJiMJ+gXK8F8cTz/yczqlUrDWg2sWpWG
38dTYOFcudziuUaQ9hz4yoTPl3o+GScCAf/OoB9iQjT+hlbmhpqGl0towruPXbo1
MbBco8Ttvuv8o6TPbsJzu2yuyxZsiMFJOJHTALSZcs9ohD6AWqnFP2ogcoUAxgXB
q2NoMzg5pUrVa3el5jVJQ2cXZ3oJJuU6FlGiWOuzgHMe+mi8A92H6LLvjfXxm9tN
j2SV3vSlgaiRi40wqr0Y
=cnAF
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2067-1
January 03, 2014
linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Catalin Marinas reported a flaw in the get_user and put_user API functions
in the Linux kernel on ARM platforms. An unprivileged local user could
exploit this flaw to gain administrator privileges. (CVE-2013-6282)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-1442-omap4 3.2.0-1442.61
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2067-1
CVE-2013-4299, CVE-2013-4470, CVE-2013-4511, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4592, CVE-2013-6282, CVE-2013-6378,
CVE-2013-6383, CVE-2013-6763, CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1442.61
[USN-2068-1] Linux kernel (Quantal HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpwYAAoJEAUvNnAY1cPY+IAP/iuB5U9vwhR+uCArLQmuVex8
0SlUpV70eaq4VQwm/7G8uLkjYg24uNo5DrrI7mMBJIUI4Wgd03x7ehtOQVkfuUBa
lEWBTtIrjPjfJy9PkkX56QnOhRyswtB0uva/XVbjLWO4/KIfOtjRyH+ki7P83E9c
cp+PUe2fI5v7FIblvQ5Ae/HgPZ7IiI/mJhPnR6QH23llwfErLcjKxGhx7g715kz4
t3LUrFCEqtLpkYmJnUkz821NbkiKi2VuMxBesWi1td5VVFw4WeLfXBXNI2Nc1Oi5
kQHie+KacFnILG60UKyrsGxsGoMaYfVXGX0ErnZkdy9EVUt6bUXFT+FR0ZDcRjIH
sfdwLnKSq/J3gjNZJ3n9Kr5hwhYGnX3H75pX53AXY/7VhN+8RrcO0pEDKMb1mHRj
UWytqzLzOMcgT8a3Bjxbi8rpaU+TAt7wlF9fWe6kg1/bVfBsCEZB+vs1Hnk0vGMQ
3YazGs3AuNlnXgdCRRRNZUuRwkPR26502I4O1LRGaWUNpmiCiXg+9T0ZdUDCk7BR
8a80ffZ8W269olziN9W7QOUXsNrkaCRo+CFSsx0/PcHKXMlkNrieyhV0npe4jFGv
4/wYUKDSGGcu9uZkEtoa6me2uzHbuGJ3XkCI7gsFu3KN1mPClOqpO0ixMBUOoGQp
KdWPgQLvZJdF0PYJgtPf
=VK63
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2068-1
January 03, 2014
linux-lts-quantal vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-quantal: Linux hardware enablement kernel from Quantal
Details:
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.5.0-45-generic 3.5.0-45.68~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2068-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-45.68~precise1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpwYAAoJEAUvNnAY1cPY+IAP/iuB5U9vwhR+uCArLQmuVex8
0SlUpV70eaq4VQwm/7G8uLkjYg24uNo5DrrI7mMBJIUI4Wgd03x7ehtOQVkfuUBa
lEWBTtIrjPjfJy9PkkX56QnOhRyswtB0uva/XVbjLWO4/KIfOtjRyH+ki7P83E9c
cp+PUe2fI5v7FIblvQ5Ae/HgPZ7IiI/mJhPnR6QH23llwfErLcjKxGhx7g715kz4
t3LUrFCEqtLpkYmJnUkz821NbkiKi2VuMxBesWi1td5VVFw4WeLfXBXNI2Nc1Oi5
kQHie+KacFnILG60UKyrsGxsGoMaYfVXGX0ErnZkdy9EVUt6bUXFT+FR0ZDcRjIH
sfdwLnKSq/J3gjNZJ3n9Kr5hwhYGnX3H75pX53AXY/7VhN+8RrcO0pEDKMb1mHRj
UWytqzLzOMcgT8a3Bjxbi8rpaU+TAt7wlF9fWe6kg1/bVfBsCEZB+vs1Hnk0vGMQ
3YazGs3AuNlnXgdCRRRNZUuRwkPR26502I4O1LRGaWUNpmiCiXg+9T0ZdUDCk7BR
8a80ffZ8W269olziN9W7QOUXsNrkaCRo+CFSsx0/PcHKXMlkNrieyhV0npe4jFGv
4/wYUKDSGGcu9uZkEtoa6me2uzHbuGJ3XkCI7gsFu3KN1mPClOqpO0ixMBUOoGQp
KdWPgQLvZJdF0PYJgtPf
=VK63
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2068-1
January 03, 2014
linux-lts-quantal vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-quantal: Linux hardware enablement kernel from Quantal
Details:
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a buffer overflow in the Ozmo
Devices USB over WiFi devices. A local user could exploit this flaw to
cause a denial of service or possibly unspecified impact. (CVE-2013-4513)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.5.0-45-generic 3.5.0-45.68~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2068-1
CVE-2013-2930, CVE-2013-4345, CVE-2013-4511, CVE-2013-4513,
CVE-2013-4514, CVE-2013-4515, CVE-2013-6383, CVE-2013-6763,
CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-45.68~precise1
[USN-2065-1] Linux kernel (EC2) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpu7AAoJEAUvNnAY1cPYv6EQALYh096AmZbxruEREUphdpQi
w55U3+YpWMglMAD48MoC/lwbEb5W8GHVowQS8Gc1SYkgPmxa5wAGOi6QfbFNyR66
NiUAS4Wike2dDeemyau4ZV0OEXjj5IZJpBh+hnxuaDbSN1y0z8Pcdnv5L/L1xp63
oiG7YJuyWzipaTkgosRmJNZy1k5Ddk6Biqk5ibQYzo/LyVPK6W7sXoS+4Vg3hixm
Oakokxh5ZOBBUIxSHPawRO/LVVwlX2HdVTN4eyEyXqRlrqXQt0UlYmZ9Ucc6mAeq
wbudBRAIZ5RUJgYn57tNDrtjWSuptjZ0bwcMt/HE2HGojra9phJit3ISURYH/L4z
gxco10c1O52rlQxMqU6DlccwqAcYhbKQczR0RKyBnB4V8+mY+hPEdZTqo/n79QpR
Q+UIjjZoXvcGS41mGp+95OdtZ5bU1hWU05maPslpgH9PNM4mr8DRcBqrS0l4fsmh
kjCzQO8DxLP6zs+NMo6n08QXotEK34Ohf7I7fUqXMNujlbMexd2RgMsEtRWmM/wv
nM7iKsi6r1f0fd8S0HSGc0IqzbLaog4elWcAL7z+KeWLOg3iqxNZlfkhR5EzNTB8
MyIuf/yJGRCAejOilE34OJtKJvz2IUQS9Bo5jH2QaAHi4l8PgMoYZOhqOnUGs60N
n+p0J+6e48JMVeyN3oKy
=V2k9
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2065-1
January 03, 2014
linux-ec2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ec2: Linux kernel for EC2
Details:
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-360-ec2 2.6.32-360.73
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2065-1
CVE-2013-4345, CVE-2013-4588, CVE-2013-6378, CVE-2013-6763
Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-360.73
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpu7AAoJEAUvNnAY1cPYv6EQALYh096AmZbxruEREUphdpQi
w55U3+YpWMglMAD48MoC/lwbEb5W8GHVowQS8Gc1SYkgPmxa5wAGOi6QfbFNyR66
NiUAS4Wike2dDeemyau4ZV0OEXjj5IZJpBh+hnxuaDbSN1y0z8Pcdnv5L/L1xp63
oiG7YJuyWzipaTkgosRmJNZy1k5Ddk6Biqk5ibQYzo/LyVPK6W7sXoS+4Vg3hixm
Oakokxh5ZOBBUIxSHPawRO/LVVwlX2HdVTN4eyEyXqRlrqXQt0UlYmZ9Ucc6mAeq
wbudBRAIZ5RUJgYn57tNDrtjWSuptjZ0bwcMt/HE2HGojra9phJit3ISURYH/L4z
gxco10c1O52rlQxMqU6DlccwqAcYhbKQczR0RKyBnB4V8+mY+hPEdZTqo/n79QpR
Q+UIjjZoXvcGS41mGp+95OdtZ5bU1hWU05maPslpgH9PNM4mr8DRcBqrS0l4fsmh
kjCzQO8DxLP6zs+NMo6n08QXotEK34Ohf7I7fUqXMNujlbMexd2RgMsEtRWmM/wv
nM7iKsi6r1f0fd8S0HSGc0IqzbLaog4elWcAL7z+KeWLOg3iqxNZlfkhR5EzNTB8
MyIuf/yJGRCAejOilE34OJtKJvz2IUQS9Bo5jH2QaAHi4l8PgMoYZOhqOnUGs60N
n+p0J+6e48JMVeyN3oKy
=V2k9
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2065-1
January 03, 2014
linux-ec2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ec2: Linux kernel for EC2
Details:
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-360-ec2 2.6.32-360.73
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2065-1
CVE-2013-4345, CVE-2013-4588, CVE-2013-6378, CVE-2013-6763
Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-360.73
[USN-2066-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpvaAAoJEAUvNnAY1cPYrIEP/3GSsXjjEtPXeFinqxuBNnhX
Sppr6dIla8ih8/qDjB7/u4uPqBsweaAPvAXFWE5MoGBzlWTkyivp2Y6dR7/rl6d6
PBQI7Rjv7r4V81l2uZSXUah4DKXO5i7P3a4/cBfgz6RtRcpUhJwX3zIWTScuGlEl
AgUKvgAEm+2NJMGXYtFlSv72MI5rPdxntKHJOWt4kgfxIDRup51uKTLu2gULwvqD
Ue2cl1tpvcE6IClSxIl/5pjOkZhUSxMVzNn6Z51ivY5ZBNstMFBjX1CriRdMmQ8/
qeeLTdpGdayc+A3nReW/8SGBieqAs/JYd43EpKup5dszxI2MR1zFW5Q4BCjIZDUC
Z+g4m62EsUW07B5qJaqlgFQMsjgMesBCvaEDO+OekS6wMZSbrP64wu5VfjxT6Auy
CU3gZgLl9EwBXWRu32gtTCkqRtenyts/DI4Z+tBu81i5KMRAX/5SogFdpvROhyFE
8CL/4RPHa0oL4FNiBYBHSEGGUzBWqD7n/bptnPyOdWbwBE8xD6U1g4DJ7pmLJ6tu
kLZUH0yYgGC3PCK1r+i48XuKzFWQ2LrQGxfuXPuTFqD15m67CIt4V/smjutVXS7Y
197iKxI/68LZKYln5fJGI17g7eblkTXT8jubezQgrJaZ1SczAZTE63paDhsOb9u2
K7kZRNlj6AhlzbspJuB4
=iFVH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2066-1
January 03, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-58-generic 3.2.0-58.88
linux-image-3.2.0-58-generic-pae 3.2.0-58.88
linux-image-3.2.0-58-highbank 3.2.0-58.88
linux-image-3.2.0-58-omap 3.2.0-58.88
linux-image-3.2.0-58-powerpc-smp 3.2.0-58.88
linux-image-3.2.0-58-powerpc64-smp 3.2.0-58.88
linux-image-3.2.0-58-virtual 3.2.0-58.88
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2066-1
CVE-2013-4299, CVE-2013-4470, CVE-2013-4511, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4592, CVE-2013-6378, CVE-2013-6383,
CVE-2013-6763, CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpvaAAoJEAUvNnAY1cPYrIEP/3GSsXjjEtPXeFinqxuBNnhX
Sppr6dIla8ih8/qDjB7/u4uPqBsweaAPvAXFWE5MoGBzlWTkyivp2Y6dR7/rl6d6
PBQI7Rjv7r4V81l2uZSXUah4DKXO5i7P3a4/cBfgz6RtRcpUhJwX3zIWTScuGlEl
AgUKvgAEm+2NJMGXYtFlSv72MI5rPdxntKHJOWt4kgfxIDRup51uKTLu2gULwvqD
Ue2cl1tpvcE6IClSxIl/5pjOkZhUSxMVzNn6Z51ivY5ZBNstMFBjX1CriRdMmQ8/
qeeLTdpGdayc+A3nReW/8SGBieqAs/JYd43EpKup5dszxI2MR1zFW5Q4BCjIZDUC
Z+g4m62EsUW07B5qJaqlgFQMsjgMesBCvaEDO+OekS6wMZSbrP64wu5VfjxT6Auy
CU3gZgLl9EwBXWRu32gtTCkqRtenyts/DI4Z+tBu81i5KMRAX/5SogFdpvROhyFE
8CL/4RPHa0oL4FNiBYBHSEGGUzBWqD7n/bptnPyOdWbwBE8xD6U1g4DJ7pmLJ6tu
kLZUH0yYgGC3PCK1r+i48XuKzFWQ2LrQGxfuXPuTFqD15m67CIt4V/smjutVXS7Y
197iKxI/68LZKYln5fJGI17g7eblkTXT8jubezQgrJaZ1SczAZTE63paDhsOb9u2
K7kZRNlj6AhlzbspJuB4
=iFVH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2066-1
January 03, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Agere Systems HERMES II Wireless PC Cards. A local user with the
CAP_NET_ADMIN capability could exploit this flaw to cause a denial of
service or possibly gain adminstrative priviliges. (CVE-2013-4514)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
driver for Beceem WIMAX chipset based devices. An unprivileged local user
could exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-4515)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
A flaw was discovered in the Linux kernel's compat ioctls for Adaptec
AACRAID scsi raid devices. An unprivileged local user could send
administrative commands to these devices potentially compromising the data
stored on the device. (CVE-2013-6383)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Evan Huus reported a buffer overflow in the Linux kernel's radiotap header
parsing. A remote attacker could cause a denial of service (buffer over-
read) via a specially crafted header. (CVE-2013-7027)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-58-generic 3.2.0-58.88
linux-image-3.2.0-58-generic-pae 3.2.0-58.88
linux-image-3.2.0-58-highbank 3.2.0-58.88
linux-image-3.2.0-58-omap 3.2.0-58.88
linux-image-3.2.0-58-powerpc-smp 3.2.0-58.88
linux-image-3.2.0-58-powerpc64-smp 3.2.0-58.88
linux-image-3.2.0-58-virtual 3.2.0-58.88
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2066-1
CVE-2013-4299, CVE-2013-4470, CVE-2013-4511, CVE-2013-4514,
CVE-2013-4515, CVE-2013-4592, CVE-2013-6378, CVE-2013-6383,
CVE-2013-6763, CVE-2013-7027
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-58.88
[USN-2064-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpudAAoJEAUvNnAY1cPYvgUP/ig4GrzoNpkCJY/jxeZeuahA
3b9V3UDkIhxkwTGsKMXJUztTu9Hg+3683tFVKxX6iXOUd9KVK9FmyiD9+JihXdO7
Pl3srYvWzVqnQASk1I+QC6eG+AoVM1vpNNlHWbB9IpjnOwxKP6ZEPQS0/yL0HMWD
AlCHtOc4Qu1C22GMp9kToK2fRm2CsQ7EeqqzZpm2H0OpelmZ2F9aRkyDfDaa7lKI
Rss0Bvm3sySZ6+ny1FV6Dr9J/my/2nbtnp9Y5XIXH1vjGoButwO8fssfoJc7U2/x
QH23z8ZsBHKr/r2B592s23S5W8D+SArm7IU1W71GNcREmBs4odGeDqNo+Qu/MUMn
XKTOHL1GGECPjmqkWeaMXPAb3ejkL8XYEk1UFhhPofcHro0Fej6pSM9FYTWIXm+n
jSw36cdVs2zmd+2qEiyb+397XsmyPJAkA8wsYR6bL2hyDDOIiCL7Vch8BOl12ETq
grJ/IP+gyfPy0o4BNBbluhLCV+unnc5bb0pVUCWKYmLALjAvrlzhxm8QxdyJKUZT
9KSVMB2fi91BH6LgLQ1m1XVeNtmNlIKj9EaHjuNo9Ul0t6XamkZBfGAWWagQXQK+
3Dc+90QznT36pow8vhaJ5gmBRA+WAdAshInBexWfnsyHyq7dGCU1ymtsDsYEakAQ
0+nNBfYaz4Hd/cRgBIvb
=RBmB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2064-1
January 03, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-55-386 2.6.32-55.117
linux-image-2.6.32-55-generic 2.6.32-55.117
linux-image-2.6.32-55-generic-pae 2.6.32-55.117
linux-image-2.6.32-55-ia64 2.6.32-55.117
linux-image-2.6.32-55-lpia 2.6.32-55.117
linux-image-2.6.32-55-powerpc 2.6.32-55.117
linux-image-2.6.32-55-powerpc-smp 2.6.32-55.117
linux-image-2.6.32-55-powerpc64-smp 2.6.32-55.117
linux-image-2.6.32-55-preempt 2.6.32-55.117
linux-image-2.6.32-55-server 2.6.32-55.117
linux-image-2.6.32-55-sparc64 2.6.32-55.117
linux-image-2.6.32-55-sparc64-smp 2.6.32-55.117
linux-image-2.6.32-55-versatile 2.6.32-55.117
linux-image-2.6.32-55-virtual 2.6.32-55.117
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2064-1
CVE-2013-4345, CVE-2013-4588, CVE-2013-6378, CVE-2013-6763
Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSxpudAAoJEAUvNnAY1cPYvgUP/ig4GrzoNpkCJY/jxeZeuahA
3b9V3UDkIhxkwTGsKMXJUztTu9Hg+3683tFVKxX6iXOUd9KVK9FmyiD9+JihXdO7
Pl3srYvWzVqnQASk1I+QC6eG+AoVM1vpNNlHWbB9IpjnOwxKP6ZEPQS0/yL0HMWD
AlCHtOc4Qu1C22GMp9kToK2fRm2CsQ7EeqqzZpm2H0OpelmZ2F9aRkyDfDaa7lKI
Rss0Bvm3sySZ6+ny1FV6Dr9J/my/2nbtnp9Y5XIXH1vjGoButwO8fssfoJc7U2/x
QH23z8ZsBHKr/r2B592s23S5W8D+SArm7IU1W71GNcREmBs4odGeDqNo+Qu/MUMn
XKTOHL1GGECPjmqkWeaMXPAb3ejkL8XYEk1UFhhPofcHro0Fej6pSM9FYTWIXm+n
jSw36cdVs2zmd+2qEiyb+397XsmyPJAkA8wsYR6bL2hyDDOIiCL7Vch8BOl12ETq
grJ/IP+gyfPy0o4BNBbluhLCV+unnc5bb0pVUCWKYmLALjAvrlzhxm8QxdyJKUZT
9KSVMB2fi91BH6LgLQ1m1XVeNtmNlIKj9EaHjuNo9Ul0t6XamkZBfGAWWagQXQK+
3Dc+90QznT36pow8vhaJ5gmBRA+WAdAshInBexWfnsyHyq7dGCU1ymtsDsYEakAQ
0+nNBfYaz4Hd/cRgBIvb
=RBmB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2064-1
January 03, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploit this flaw to cause a denial of service (memory
corruption) or possibly gain privileges. (CVE-2013-6763)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-55-386 2.6.32-55.117
linux-image-2.6.32-55-generic 2.6.32-55.117
linux-image-2.6.32-55-generic-pae 2.6.32-55.117
linux-image-2.6.32-55-ia64 2.6.32-55.117
linux-image-2.6.32-55-lpia 2.6.32-55.117
linux-image-2.6.32-55-powerpc 2.6.32-55.117
linux-image-2.6.32-55-powerpc-smp 2.6.32-55.117
linux-image-2.6.32-55-powerpc64-smp 2.6.32-55.117
linux-image-2.6.32-55-preempt 2.6.32-55.117
linux-image-2.6.32-55-server 2.6.32-55.117
linux-image-2.6.32-55-sparc64 2.6.32-55.117
linux-image-2.6.32-55-sparc64-smp 2.6.32-55.117
linux-image-2.6.32-55-versatile 2.6.32-55.117
linux-image-2.6.32-55-virtual 2.6.32-55.117
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2064-1
CVE-2013-4345, CVE-2013-4588, CVE-2013-6378, CVE-2013-6763
Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-55.117
Thursday, January 2, 2014
[CentOS-announce] CEBA-2014:0003 CentOS 6 ethtool Update
CentOS Errata and Bugfix Advisory 2014:0003
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-0003.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f1987173982e5053872b6856a787d63011339765aaa32d443006d803283e20fb ethtool-3.5-1.2.el6_5.i686.rpm
x86_64:
24104b292bc87a7969b762d2ec5f2484ac0f2d40b744e5d8064666fe713d09af ethtool-3.5-1.2.el6_5.x86_64.rpm
Source:
8a2e8291662222593b8eb02c7c076527b074df73d7e63babc4d51e299182e2e1 ethtool-3.5-1.2.el6_5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-0003.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f1987173982e5053872b6856a787d63011339765aaa32d443006d803283e20fb ethtool-3.5-1.2.el6_5.i686.rpm
x86_64:
24104b292bc87a7969b762d2ec5f2484ac0f2d40b744e5d8064666fe713d09af ethtool-3.5-1.2.el6_5.x86_64.rpm
Source:
8a2e8291662222593b8eb02c7c076527b074df73d7e63babc4d51e299182e2e1 ethtool-3.5-1.2.el6_5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2014:0002 CentOS 5 cman Update
CentOS Errata and Bugfix Advisory 2014:0002
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-0002.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
dde5d14bade8d2b230b1ec8bab7fce5ac7a975da5f0b790a659e2dc82da92f37 cman-2.0.115-118.el5.3.i386.rpm
e4ac83c90ee260258a6a30f6a43ee395279003e02f4194520d128005ffeb1ea6 cman-devel-2.0.115-118.el5.3.i386.rpm
x86_64:
fc9b0732deb33f4d3b1bc8eff57a95cb84d53617c050f89aa95c1f402b2ce991 cman-2.0.115-118.el5.3.x86_64.rpm
e4ac83c90ee260258a6a30f6a43ee395279003e02f4194520d128005ffeb1ea6 cman-devel-2.0.115-118.el5.3.i386.rpm
cb3af8aedef8c35cfbd78aba591ad1a88f36025b2ddd400fd15a7711c008c796 cman-devel-2.0.115-118.el5.3.x86_64.rpm
Source:
484688b49783f3993702854d1b6fa1d583dbe618fdc2d9d54681546c4a480fff cman-2.0.115-118.el5.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-0002.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
dde5d14bade8d2b230b1ec8bab7fce5ac7a975da5f0b790a659e2dc82da92f37 cman-2.0.115-118.el5.3.i386.rpm
e4ac83c90ee260258a6a30f6a43ee395279003e02f4194520d128005ffeb1ea6 cman-devel-2.0.115-118.el5.3.i386.rpm
x86_64:
fc9b0732deb33f4d3b1bc8eff57a95cb84d53617c050f89aa95c1f402b2ce991 cman-2.0.115-118.el5.3.x86_64.rpm
e4ac83c90ee260258a6a30f6a43ee395279003e02f4194520d128005ffeb1ea6 cman-devel-2.0.115-118.el5.3.i386.rpm
cb3af8aedef8c35cfbd78aba591ad1a88f36025b2ddd400fd15a7711c008c796 cman-devel-2.0.115-118.el5.3.x86_64.rpm
Source:
484688b49783f3993702854d1b6fa1d583dbe618fdc2d9d54681546c4a480fff cman-2.0.115-118.el5.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Monday, December 30, 2013
[FreeBSD-Announce] Faces of FreeBSD - Isabell Long
Dear FreeBSD Community,
Thank you to everyone who has helped us raise $656,166 so far this year. We have another $75,000 in pledges too. There are only 2 days left for us to reach our goal of raising $1,000,000 for 2013! We can't do this without your support. You can help us by promoting our fundraising campaign on your websites, FaceBook pages, bringing it up in your conversations with friends, and telling your company how they can donate too.
We are excited to share another Faces of FreeBSD story for 2013. This is a
chance for us to spotlight different people who contribute to FreeBSD in various ways.
Let us introduce you to Isabell Long. In 2011 she decided to participate in the Google Code-In contest, where she completed documentation-related tasks and became heavily involved in the documentation project afterwards. She is now a documentation committer. The Foundation helped her attend EuroBSDcon 2013 where she was able to participate in the documentation sessions.
You can read her story here:
http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-isabell-long.html
Please consider making a donation to help us continue and increase our
support of the FreeBSD Project and community worldwide! To make a
donation go to:
http://www.freebsdfoundation.org/donate/
Thank You,
The FreeBSD Foundation
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
Thank you to everyone who has helped us raise $656,166 so far this year. We have another $75,000 in pledges too. There are only 2 days left for us to reach our goal of raising $1,000,000 for 2013! We can't do this without your support. You can help us by promoting our fundraising campaign on your websites, FaceBook pages, bringing it up in your conversations with friends, and telling your company how they can donate too.
We are excited to share another Faces of FreeBSD story for 2013. This is a
chance for us to spotlight different people who contribute to FreeBSD in various ways.
Let us introduce you to Isabell Long. In 2011 she decided to participate in the Google Code-In contest, where she completed documentation-related tasks and became heavily involved in the documentation project afterwards. She is now a documentation committer. The Foundation helped her attend EuroBSDcon 2013 where she was able to participate in the documentation sessions.
You can read her story here:
http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-isabell-long.html
Please consider making a donation to help us continue and increase our
support of the FreeBSD Project and community worldwide! To make a
donation go to:
http://www.freebsdfoundation.org/donate/
Thank You,
The FreeBSD Foundation
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
Subscribe to:
Posts (Atom)