-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBAgAGBQJUBjSnAAoJEGEfvezVlG4Pjf0H/jsHcV2yrF6q8/6wWzCl8B6W
nCx7pi3T2aj3Vzw5OAS09dcS4VSiYJC+Ub5/tLKQDvwYY9gAeg1j+So7lG9IQPKE
GUPuKPq17NYW7YIhKHKuag59zagDnYKVOpiMASvzdt2oNa5cGaOar+V1CDkIMYi7
f9tnNd6iMedtc11hKgGJaLqCeRyrM9j4u6QPjf6LHOtKmkIclPTMrMDni8JlqWyV
6lCNn77rpNJyIxhgUXuQM5B5cEgFTw6R9TQSXH3eRCVSlLOLDdXLLKoQ4lb/9954
GGb7chSNeJzVGBVUc9+AYpMut2WZzc2SDqGMSPCPoooEhbt3CWHq6aFGVGrUdOE=
=vFYR
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2326-1
September 02, 2014
oxide-qt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Oxide.
Software Description:
- oxide-qt: Web browser engine library for Qt (QML plugin)
Details:
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3168)
A use-after-free was discovered in the DOM implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3169)
A use-after-free was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-3171)
It was discovered that WebGL clear calls did not interact properly with
the state of a draw buffer. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service. (CVE-2014-3173)
A threading issue was discovered in the Web Audio API during attempts to
update biquad filter coefficients. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service. (CVE-2014-3174)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3175)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
liboxideqtcore0 1.1.2-0ubuntu0.14.04.1
oxideqt-codecs 1.1.2-0ubuntu0.14.04.1
oxideqt-codecs-extra 1.1.2-0ubuntu0.14.04.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2326-1
CVE-2014-3168, CVE-2014-3169, CVE-2014-3171, CVE-2014-3173,
CVE-2014-3174, CVE-2014-3175
Package Information:
https://launchpad.net/ubuntu/+source/oxide-qt/1.1.2-0ubuntu0.14.04.1
Tuesday, September 2, 2014
[announce] NYC*BUG Wednesday Sept 3
Sorry for the delay...
2014-09-03 18:45, about.com (1500 Broadway, 43rd Street, 6th Floor)
Notice: RSVP to rsvp at nycbug.org and bring photo ID. RSVPs must be
received by 2 PM, day-of.
This month's meeting will be a discussion about the status of last
month's OpenBSD porting, plus a short presentation on the deprecation of
FreeBSDs pkg_* tools and its replacement with pkgng.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
2014-09-03 18:45, about.com (1500 Broadway, 43rd Street, 6th Floor)
Notice: RSVP to rsvp at nycbug.org and bring photo ID. RSVPs must be
received by 2 PM, day-of.
This month's meeting will be a discussion about the status of last
month's OpenBSD porting, plus a short presentation on the deprecation of
FreeBSDs pkg_* tools and its replacement with pkgng.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
[USN-2329-1] Firefox vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBAgAGBQJUBhGZAAoJEGEfvezVlG4PzFwH/2OoORF4CxMB4BxeHHR0U+I5
e+L1kkob5IEIUv3GgzIApnDc1T35kRQJdGQ5tsd49z3BSeG1KZLToYjUoqSA2qHm
fCD2gWB+xRZV4K+d3dRGDZF/O8jDtM3xD1H2u6UwGkAai+tukiVO38kAgNIR7N68
fy/FQ16B0Ha9Di64bFofKngnrpmnES5ocOXWtxHv3C/GFO+kYRugom34cChTCvnR
ygPjrsKYw66znMYgB8jyNs9ePcXTdlYJeFIFPXNY6n2izu/FEzK3ZFpGSWwuMK6+
byQBRcdkgY6M/TYflZZpHF8VzCVnDTbERtvbk4mg1h/JoNHae1H9yn/Hvj/I9uI=
=u3Z0
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2329-1
September 02, 2014
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Jan de Mooij, Christian Holler, Karl Tomlinson, Randell Jesup, Gary Kwong,
Jesse Ruderman, JW Wang and David Weir discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2014-1553,
CVE-2014-1554, CVE-2014-1562)
Abhishek Arya discovered a use-after-free during DOM interactions with
SVG. If a user were tricked in to opening a specially crafted page, an
attacker could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2014-1563)
Michal Zalewski discovered that memory is not initialized properly during
GIF rendering in some circumstances. If a user were tricked in to opening
a specially crafted page, an attacker could potentially exploit this to
steal confidential information. (CVE-2014-1564)
Holger Fuhrmannek discovered an out-of-bounds read in Web Audio. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via
application crash or steal confidential information. (CVE-2014-1565)
A use-after-free was discovered during text layout in some circumstances.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2014-1567)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
firefox 32.0+build1-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox 32.0+build1-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2329-1
CVE-2014-1553, CVE-2014-1554, CVE-2014-1562, CVE-2014-1563,
CVE-2014-1564, CVE-2014-1565, CVE-2014-1567
Package Information:
https://launchpad.net/ubuntu/+source/firefox/32.0+build1-0ubuntu0.14.04.1
https://launchpad.net/ubuntu/+source/firefox/32.0+build1-0ubuntu0.12.04.1
Version: GnuPG v1
iQEcBAEBAgAGBQJUBhGZAAoJEGEfvezVlG4PzFwH/2OoORF4CxMB4BxeHHR0U+I5
e+L1kkob5IEIUv3GgzIApnDc1T35kRQJdGQ5tsd49z3BSeG1KZLToYjUoqSA2qHm
fCD2gWB+xRZV4K+d3dRGDZF/O8jDtM3xD1H2u6UwGkAai+tukiVO38kAgNIR7N68
fy/FQ16B0Ha9Di64bFofKngnrpmnES5ocOXWtxHv3C/GFO+kYRugom34cChTCvnR
ygPjrsKYw66znMYgB8jyNs9ePcXTdlYJeFIFPXNY6n2izu/FEzK3ZFpGSWwuMK6+
byQBRcdkgY6M/TYflZZpHF8VzCVnDTbERtvbk4mg1h/JoNHae1H9yn/Hvj/I9uI=
=u3Z0
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2329-1
September 02, 2014
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Jan de Mooij, Christian Holler, Karl Tomlinson, Randell Jesup, Gary Kwong,
Jesse Ruderman, JW Wang and David Weir discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2014-1553,
CVE-2014-1554, CVE-2014-1562)
Abhishek Arya discovered a use-after-free during DOM interactions with
SVG. If a user were tricked in to opening a specially crafted page, an
attacker could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2014-1563)
Michal Zalewski discovered that memory is not initialized properly during
GIF rendering in some circumstances. If a user were tricked in to opening
a specially crafted page, an attacker could potentially exploit this to
steal confidential information. (CVE-2014-1564)
Holger Fuhrmannek discovered an out-of-bounds read in Web Audio. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via
application crash or steal confidential information. (CVE-2014-1565)
A use-after-free was discovered during text layout in some circumstances.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2014-1567)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
firefox 32.0+build1-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox 32.0+build1-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2329-1
CVE-2014-1553, CVE-2014-1554, CVE-2014-1562, CVE-2014-1563,
CVE-2014-1564, CVE-2014-1565, CVE-2014-1567
Package Information:
https://launchpad.net/ubuntu/+source/firefox/32.0+build1-0ubuntu0.14.04.1
https://launchpad.net/ubuntu/+source/firefox/32.0+build1-0ubuntu0.12.04.1
[USN-2337-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgb3AAoJEAUvNnAY1cPYyv8QAKiIUCG1qNTSA8B5fesjOwRP
O4vnqhT5BvZYw/4AwW6nZ5YK6P+pnAsxDWh+x7pxWzsoRuiFkJdmsbpjNgAqtAl8
/817GFkqHkbHstq/VzV0LSX+71BedtiVr2yST4unILZS7+go0DLjlWj/MIOhm9ZI
8dI1l70aF2xa17dxu7s2tI66iHDEX9xiwXgVn8HLIsLqn3DKslBHDq8aw4bOmEJ+
Esczk9YxpXkBMnZXPAbUOnziVgUNh9zTMDoIaybVXtVLAjRaJwyyMomOsaAReWHc
QI4Xi6MQKCiZLu0kOBF1iu225uCAz05tsnFUto9zZXQkzLV6XJGSnQNru81uubfu
/28IgWtA7MK2nq2g+pHd0Z4u7v8KE8g+XtpkgKPvfb9o1J30j5ihn05leLq+GaUk
Lx14h6qiENNEmtXlo3xxK0xGLajpw9fxXaf0Wgpn3pti2wXHZGTj3/M1zUf67J30
aXe8/9BI9mXAfAljlgI3woDG6/5W9Vj2EsFna9B2rRACFOf2GkqOQtxbvmz5jFEG
qt0Tklf4p6AlXbqeJtS7NFf9M24DVm+QCxA65PCokJeyjeUUnmc9fy8PlqS12DhH
6FPalD6fF7mqt4bzyb2W2ZCMURjlVtoLc/lUF1cfSh3rfgI6Cr2o3w1+DEHvo18v
x3vhhpGYK2dXHTup5WRr
=Y3o9
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2337-1
September 02, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of user
namespaces with respect to inode permissions. A local user could exploit
this flaw by creating a user namespace to gain administrative privileges.
(CVE-2014-4014)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Vasily Averin discover a reference count flaw during attempts to umount in
conjunction with a symlink. A local user could exploit this flaw to cause a
denial of service (memory consumption or use after free) or possibly have
other unspecified impact. (CVE-2014-5045)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-35-generic 3.13.0-35.62
linux-image-3.13.0-35-generic-lpae 3.13.0-35.62
linux-image-3.13.0-35-lowlatency 3.13.0-35.62
linux-image-3.13.0-35-powerpc-e500 3.13.0-35.62
linux-image-3.13.0-35-powerpc-e500mc 3.13.0-35.62
linux-image-3.13.0-35-powerpc-smp 3.13.0-35.62
linux-image-3.13.0-35-powerpc64-emb 3.13.0-35.62
linux-image-3.13.0-35-powerpc64-smp 3.13.0-35.62
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2337-1
CVE-2014-0155, CVE-2014-0181, CVE-2014-0206, CVE-2014-4014,
CVE-2014-4027, CVE-2014-4171, CVE-2014-4508, CVE-2014-4652,
CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, CVE-2014-4656,
CVE-2014-4667, CVE-2014-5045
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-35.62
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgb3AAoJEAUvNnAY1cPYyv8QAKiIUCG1qNTSA8B5fesjOwRP
O4vnqhT5BvZYw/4AwW6nZ5YK6P+pnAsxDWh+x7pxWzsoRuiFkJdmsbpjNgAqtAl8
/817GFkqHkbHstq/VzV0LSX+71BedtiVr2yST4unILZS7+go0DLjlWj/MIOhm9ZI
8dI1l70aF2xa17dxu7s2tI66iHDEX9xiwXgVn8HLIsLqn3DKslBHDq8aw4bOmEJ+
Esczk9YxpXkBMnZXPAbUOnziVgUNh9zTMDoIaybVXtVLAjRaJwyyMomOsaAReWHc
QI4Xi6MQKCiZLu0kOBF1iu225uCAz05tsnFUto9zZXQkzLV6XJGSnQNru81uubfu
/28IgWtA7MK2nq2g+pHd0Z4u7v8KE8g+XtpkgKPvfb9o1J30j5ihn05leLq+GaUk
Lx14h6qiENNEmtXlo3xxK0xGLajpw9fxXaf0Wgpn3pti2wXHZGTj3/M1zUf67J30
aXe8/9BI9mXAfAljlgI3woDG6/5W9Vj2EsFna9B2rRACFOf2GkqOQtxbvmz5jFEG
qt0Tklf4p6AlXbqeJtS7NFf9M24DVm+QCxA65PCokJeyjeUUnmc9fy8PlqS12DhH
6FPalD6fF7mqt4bzyb2W2ZCMURjlVtoLc/lUF1cfSh3rfgI6Cr2o3w1+DEHvo18v
x3vhhpGYK2dXHTup5WRr
=Y3o9
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2337-1
September 02, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of user
namespaces with respect to inode permissions. A local user could exploit
this flaw by creating a user namespace to gain administrative privileges.
(CVE-2014-4014)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Vasily Averin discover a reference count flaw during attempts to umount in
conjunction with a symlink. A local user could exploit this flaw to cause a
denial of service (memory consumption or use after free) or possibly have
other unspecified impact. (CVE-2014-5045)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-35-generic 3.13.0-35.62
linux-image-3.13.0-35-generic-lpae 3.13.0-35.62
linux-image-3.13.0-35-lowlatency 3.13.0-35.62
linux-image-3.13.0-35-powerpc-e500 3.13.0-35.62
linux-image-3.13.0-35-powerpc-e500mc 3.13.0-35.62
linux-image-3.13.0-35-powerpc-smp 3.13.0-35.62
linux-image-3.13.0-35-powerpc64-emb 3.13.0-35.62
linux-image-3.13.0-35-powerpc64-smp 3.13.0-35.62
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2337-1
CVE-2014-0155, CVE-2014-0181, CVE-2014-0206, CVE-2014-4014,
CVE-2014-4027, CVE-2014-4171, CVE-2014-4508, CVE-2014-4652,
CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, CVE-2014-4656,
CVE-2014-4667, CVE-2014-5045
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-35.62
[USN-2336-1] Linux kernel (Trusty HWE) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgbYAAoJEAUvNnAY1cPYVDYQAJzFRSIU+mzOMDbYrrjWv+Q1
cX3H0Hp6YNPOEvpDEWQBYtYQx07lhp9/vGQza1FRhh9OUcSV+un4Metg1EdlXxZG
WMZszQigXCe2/nxNXllFhzjGYy2Qtx0Rn4CRmd0vRXbFk/50WP1jYXV+XSqj4422
b1nQch9RdDpKO1FIkDEaZ2PGp2AaYVieZl3AFTuIzLdhLcU8w0wH/Y6CSwh1lJ3q
QqjLk0lGTYWlKj5j9VwsO/Z+5yBJwJNCNJuD5d4jUXxeD07oXJkb0p7V/XLlc7zQ
uVaa9DJQM+EoHuqN//IU0UksLvvg/9Mw++OPrrAatSX12ulPR8mkfkm0nyb9gCrn
2J56uMdnjgxnOsoxcxRLcJAJMZoXFQ6ojUKKBoXrDeSbgyoNEK/5pzcOoBbTOYLX
6sEHX+U/JMXoWhycvqmPoT7BJFC1KMZ/RfHNeWgWxjRP6zfvY3rUZLLHVQimGGwH
3ed1JuqG5lX3JhbvF0T2UZdgJ0LK8rO2IZjN58iUz7k0Wchzyj8I6qGHQvH2VO4B
+UqZeKyLqBMtuXobz/NRxbqe7/Mtgu01d6o2w1tzfBVXKpQECczcXaA6yIxpB8+s
a2wayb+gFauQHRhw+DOT2S11fAGB3Fm2jdp1K7GIK8jcKesn8PwONP1Fa9XXo1KK
ebDZo/URSJwtcUzM69Y2
=Z3sM
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2336-1
September 02, 2014
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty
Details:
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of user
namespaces with respect to inode permissions. A local user could exploit
this flaw by creating a user namespace to gain administrative privileges.
(CVE-2014-4014)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Vasily Averin discover a reference count flaw during attempts to umount in
conjunction with a symlink. A local user could exploit this flaw to cause a
denial of service (memory consumption or use after free) or possibly have
other unspecified impact. (CVE-2014-5045)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-35-generic 3.13.0-35.62~precise1
linux-image-3.13.0-35-generic-lpae 3.13.0-35.62~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2336-1
CVE-2014-0155, CVE-2014-0181, CVE-2014-0206, CVE-2014-4014,
CVE-2014-4027, CVE-2014-4171, CVE-2014-4508, CVE-2014-4652,
CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, CVE-2014-4656,
CVE-2014-4667, CVE-2014-5045
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-35.62~precise1
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgbYAAoJEAUvNnAY1cPYVDYQAJzFRSIU+mzOMDbYrrjWv+Q1
cX3H0Hp6YNPOEvpDEWQBYtYQx07lhp9/vGQza1FRhh9OUcSV+un4Metg1EdlXxZG
WMZszQigXCe2/nxNXllFhzjGYy2Qtx0Rn4CRmd0vRXbFk/50WP1jYXV+XSqj4422
b1nQch9RdDpKO1FIkDEaZ2PGp2AaYVieZl3AFTuIzLdhLcU8w0wH/Y6CSwh1lJ3q
QqjLk0lGTYWlKj5j9VwsO/Z+5yBJwJNCNJuD5d4jUXxeD07oXJkb0p7V/XLlc7zQ
uVaa9DJQM+EoHuqN//IU0UksLvvg/9Mw++OPrrAatSX12ulPR8mkfkm0nyb9gCrn
2J56uMdnjgxnOsoxcxRLcJAJMZoXFQ6ojUKKBoXrDeSbgyoNEK/5pzcOoBbTOYLX
6sEHX+U/JMXoWhycvqmPoT7BJFC1KMZ/RfHNeWgWxjRP6zfvY3rUZLLHVQimGGwH
3ed1JuqG5lX3JhbvF0T2UZdgJ0LK8rO2IZjN58iUz7k0Wchzyj8I6qGHQvH2VO4B
+UqZeKyLqBMtuXobz/NRxbqe7/Mtgu01d6o2w1tzfBVXKpQECczcXaA6yIxpB8+s
a2wayb+gFauQHRhw+DOT2S11fAGB3Fm2jdp1K7GIK8jcKesn8PwONP1Fa9XXo1KK
ebDZo/URSJwtcUzM69Y2
=Z3sM
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2336-1
September 02, 2014
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty
Details:
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of user
namespaces with respect to inode permissions. A local user could exploit
this flaw by creating a user namespace to gain administrative privileges.
(CVE-2014-4014)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Vasily Averin discover a reference count flaw during attempts to umount in
conjunction with a symlink. A local user could exploit this flaw to cause a
denial of service (memory consumption or use after free) or possibly have
other unspecified impact. (CVE-2014-5045)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-35-generic 3.13.0-35.62~precise1
linux-image-3.13.0-35-generic-lpae 3.13.0-35.62~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2336-1
CVE-2014-0155, CVE-2014-0181, CVE-2014-0206, CVE-2014-4014,
CVE-2014-4027, CVE-2014-4171, CVE-2014-4508, CVE-2014-4652,
CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, CVE-2014-4656,
CVE-2014-4667, CVE-2014-5045
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-35.62~precise1
[USN-2335-1] Linux kernel (OMAP4) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBga4AAoJEAUvNnAY1cPYEakQAJld7rMDbx+u3Oo0G5lmzYVq
6IaZc/gEhXwu2/4GfYme3kqOhcM9yYXqN92R56bYwLHAlhmXS/aJnY6/xtTPz7Xp
NDDF5dmFGVEdylkhmm9jrSOmbL0kHZwZGeUoEiSjU+HZfsjUf7oG+bVZSAL0dQuh
8IMXqaYnsmZCxP3yqeECGqM8jqDnS0Y/YGJp7UghBAacR+7KeqTJDuvIuWIq2mjh
OVm49wfk6QkEIH9x0h9mqg+7xggbzaGrjkGmutdMq+dX+3Ff4JWC8uVDRtEiS6FR
dhhwOQo9lyoq1df8FwktLODMi3fENbsoLi9NCPKKk6+Y8r6nGlnxGUS1fceHMMcl
nksB7ZtmbKM1IHQ9Wn6qVR6me/uOksuyCDnoCsCCEPxXoNVR8pdOXR2aWLllhmX4
QJmCDtRidbwRhzxjEpw5mhnbW195ie809suRgva9KdkCCSAC+NYWfDbt1HWNAUU0
P+qymgHi82/NnaOw8bGwyQhHAQm4mrGEuIIKHw08/9hWeQicp4aHYiRk0nwLr2yG
u0RvXVyDeRymg7IePh0de80LRJ9SoMz0Al4SA/AtTsroRBxbbCIrVenUaMOzx6Yo
waH3u2y1ImZFSOxk0ZmuUjlu1r33FnK787tisLPQuk4WA1JvjYmCF2TFanWapyqN
GxHmpC0+LiCJfW6UPbK6
=KmH7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2335-1
September 02, 2014
linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-1452-omap4 3.2.0-1452.72
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2335-1
CVE-2014-3917, CVE-2014-4027, CVE-2014-4171, CVE-2014-4652,
CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, CVE-2014-4656,
CVE-2014-4667, CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1452.72
Version: GnuPG v1
iQIcBAEBCgAGBQJUBga4AAoJEAUvNnAY1cPYEakQAJld7rMDbx+u3Oo0G5lmzYVq
6IaZc/gEhXwu2/4GfYme3kqOhcM9yYXqN92R56bYwLHAlhmXS/aJnY6/xtTPz7Xp
NDDF5dmFGVEdylkhmm9jrSOmbL0kHZwZGeUoEiSjU+HZfsjUf7oG+bVZSAL0dQuh
8IMXqaYnsmZCxP3yqeECGqM8jqDnS0Y/YGJp7UghBAacR+7KeqTJDuvIuWIq2mjh
OVm49wfk6QkEIH9x0h9mqg+7xggbzaGrjkGmutdMq+dX+3Ff4JWC8uVDRtEiS6FR
dhhwOQo9lyoq1df8FwktLODMi3fENbsoLi9NCPKKk6+Y8r6nGlnxGUS1fceHMMcl
nksB7ZtmbKM1IHQ9Wn6qVR6me/uOksuyCDnoCsCCEPxXoNVR8pdOXR2aWLllhmX4
QJmCDtRidbwRhzxjEpw5mhnbW195ie809suRgva9KdkCCSAC+NYWfDbt1HWNAUU0
P+qymgHi82/NnaOw8bGwyQhHAQm4mrGEuIIKHw08/9hWeQicp4aHYiRk0nwLr2yG
u0RvXVyDeRymg7IePh0de80LRJ9SoMz0Al4SA/AtTsroRBxbbCIrVenUaMOzx6Yo
waH3u2y1ImZFSOxk0ZmuUjlu1r33FnK787tisLPQuk4WA1JvjYmCF2TFanWapyqN
GxHmpC0+LiCJfW6UPbK6
=KmH7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2335-1
September 02, 2014
linux-ti-omap4 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-1452-omap4 3.2.0-1452.72
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2335-1
CVE-2014-3917, CVE-2014-4027, CVE-2014-4171, CVE-2014-4652,
CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, CVE-2014-4656,
CVE-2014-4667, CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1452.72
[USN-2334-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgaCAAoJEAUvNnAY1cPY+PgP/AweLxG6DzIda//u6kIo93jP
3slfoidr5IdtI7v1XhRp80ArBuiZ5GzKfhA9L0msW786qKyfebXjtwhFospus6dA
FjAfXvb8y6BiZKzpPjLyCvBYKnvqgxJT9h72KW4Av1/acmnvSuetdWPADO03Su34
2/eN36htCdQ6+9Yu/SaxrAv6rVQAqCZjiV7Vc9k4G8xLeHg/N31UW3sj6leawvfc
y4zZE2nkW5WpSESnmAUIhKzkT+R0lYGRuo8fmDSXzSZ/10Y90NGCqCHVjsVehHV7
hLeth1/wKOAmAIAlxrSZug1D8bxZQN4GW38dHeExildM+Yjaakf7w4TLTcs72SW4
HYLg/bz7ThyqMKAcepZzNF6seAIM63TQxUF1hKeqZFA7PJqE956S0LLEO3v8NtX7
JQfSzvUs/wzIoToXbRLqt848HLHBh4Lp75tJ5qxwR78bqAcaA189oa4D2CPVpG0a
NJ1HW2GwK/VDj1ePzOW8ob+N/t/yzhqgrrwr1SLmHLhKtjWN2CmMJyZ3F20doxgG
ywdg2s0KGHXAwiVR3fJHp+lpfOuqqjjtlcih74VfOi63UD8HBgfnFFMnDmInh3Cg
WgPiFSZ3vXtqNIeRoKi0diIHJYyXMfuEv2IIjpl6XymoTiDy8L/DFe6uq0A32Uqu
Zks8Cw/4RIbGcTiiYrKM
=JxlP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2334-1
September 02, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-68-generic 3.2.0-68.102
linux-image-3.2.0-68-generic-pae 3.2.0-68.102
linux-image-3.2.0-68-highbank 3.2.0-68.102
linux-image-3.2.0-68-omap 3.2.0-68.102
linux-image-3.2.0-68-powerpc-smp 3.2.0-68.102
linux-image-3.2.0-68-powerpc64-smp 3.2.0-68.102
linux-image-3.2.0-68-virtual 3.2.0-68.102
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2334-1
CVE-2014-3917, CVE-2014-4027, CVE-2014-4171, CVE-2014-4508,
CVE-2014-4652, CVE-2014-4653, CVE-2014-4654, CVE-2014-4655,
CVE-2014-4656, CVE-2014-4667, CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-68.102
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgaCAAoJEAUvNnAY1cPY+PgP/AweLxG6DzIda//u6kIo93jP
3slfoidr5IdtI7v1XhRp80ArBuiZ5GzKfhA9L0msW786qKyfebXjtwhFospus6dA
FjAfXvb8y6BiZKzpPjLyCvBYKnvqgxJT9h72KW4Av1/acmnvSuetdWPADO03Su34
2/eN36htCdQ6+9Yu/SaxrAv6rVQAqCZjiV7Vc9k4G8xLeHg/N31UW3sj6leawvfc
y4zZE2nkW5WpSESnmAUIhKzkT+R0lYGRuo8fmDSXzSZ/10Y90NGCqCHVjsVehHV7
hLeth1/wKOAmAIAlxrSZug1D8bxZQN4GW38dHeExildM+Yjaakf7w4TLTcs72SW4
HYLg/bz7ThyqMKAcepZzNF6seAIM63TQxUF1hKeqZFA7PJqE956S0LLEO3v8NtX7
JQfSzvUs/wzIoToXbRLqt848HLHBh4Lp75tJ5qxwR78bqAcaA189oa4D2CPVpG0a
NJ1HW2GwK/VDj1ePzOW8ob+N/t/yzhqgrrwr1SLmHLhKtjWN2CmMJyZ3F20doxgG
ywdg2s0KGHXAwiVR3fJHp+lpfOuqqjjtlcih74VfOi63UD8HBgfnFFMnDmInh3Cg
WgPiFSZ3vXtqNIeRoKi0diIHJYyXMfuEv2IIjpl6XymoTiDy8L/DFe6uq0A32Uqu
Zks8Cw/4RIbGcTiiYrKM
=JxlP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2334-1
September 02, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.2.0-68-generic 3.2.0-68.102
linux-image-3.2.0-68-generic-pae 3.2.0-68.102
linux-image-3.2.0-68-highbank 3.2.0-68.102
linux-image-3.2.0-68-omap 3.2.0-68.102
linux-image-3.2.0-68-powerpc-smp 3.2.0-68.102
linux-image-3.2.0-68-powerpc64-smp 3.2.0-68.102
linux-image-3.2.0-68-virtual 3.2.0-68.102
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2334-1
CVE-2014-3917, CVE-2014-4027, CVE-2014-4171, CVE-2014-4508,
CVE-2014-4652, CVE-2014-4653, CVE-2014-4654, CVE-2014-4655,
CVE-2014-4656, CVE-2014-4667, CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-68.102
[USN-2331-1] LibreOffice vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgZgAAoJEAUvNnAY1cPYLB4QALtmC5N4PQn96opZNgQC6p/N
9kolfHZynDZnsU4ny8tEgenA/bOBye07Tt9N6Xb7S53cx1rZ8X3gJhPVMi4VyUtz
uM3Qc3gfp1nhjTmNOgaGcGkxd1GTzmIc3xjPQYJuRJR8Sg4xzQCKcwdiVcfyo38+
TtbBso0rRRhpXD+llWrre9ZWGxfqa9+wvZ3GSVT8YVVmVFMgaK4V4OQtIh0COfyT
rO5kgo6UsJbSc7kVeKwkKPPVe2CWoOIi1Sh67ZBAjw87fz1np0tFhGaIri+gZLtt
3p/bxqzAyrc1xO7vHq5emrHu7iyucen4nS98hAN9S8NdMht8cIQIW5zkC+mZhJ8K
Z5ePWxY/VaoePvl0/54KapP8rp1/m8/sX2Mkw8xAWr+yZmi/Vme5DCX7vf+XFUlH
NTRrkT302CUmraFBQKL9hWXM3Xy89jJHgTfLS/S4RPXHQ9yeIoUi5lMeVy4RtIgo
Zfr7uVfopc98d1XuMwvZKZg8bAZBxBrpoL9NbGvn9MZa9tEXTmLiLByF4Ixx4Ov4
ugHZIPIgoIRl8L7J9WQ47+oVwASqR86q9QWUNnZCmF+KngjreHz+dhGDLv5I7bFK
tNvgEOcBmIsBgqgmda9pH9HEJhuRXQkXLt9pZwMX+BjQMoTyuIr/xmSX1RPTNuIP
P261yON+J92Wt7V093zI
=x8zB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2331-1
September 02, 2014
libreoffice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
LibreOffice Calc could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- libreoffice: Office productivity suite
Details:
Rohan Durve and James Kettle discovered LibreOffice Calc sometimes allowed
for command injection when opening spreadsheets. If a user were tricked
into opening a crafted Calc spreadsheet, an attacker could exploit this to
run programs as your login.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libreoffice-core 1:4.2.6.3-0ubuntu1
After a standard system update you need to restart LibreOffice to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2331-1
CVE-2014-3524
Package Information:
https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.6.3-0ubuntu1
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgZgAAoJEAUvNnAY1cPYLB4QALtmC5N4PQn96opZNgQC6p/N
9kolfHZynDZnsU4ny8tEgenA/bOBye07Tt9N6Xb7S53cx1rZ8X3gJhPVMi4VyUtz
uM3Qc3gfp1nhjTmNOgaGcGkxd1GTzmIc3xjPQYJuRJR8Sg4xzQCKcwdiVcfyo38+
TtbBso0rRRhpXD+llWrre9ZWGxfqa9+wvZ3GSVT8YVVmVFMgaK4V4OQtIh0COfyT
rO5kgo6UsJbSc7kVeKwkKPPVe2CWoOIi1Sh67ZBAjw87fz1np0tFhGaIri+gZLtt
3p/bxqzAyrc1xO7vHq5emrHu7iyucen4nS98hAN9S8NdMht8cIQIW5zkC+mZhJ8K
Z5ePWxY/VaoePvl0/54KapP8rp1/m8/sX2Mkw8xAWr+yZmi/Vme5DCX7vf+XFUlH
NTRrkT302CUmraFBQKL9hWXM3Xy89jJHgTfLS/S4RPXHQ9yeIoUi5lMeVy4RtIgo
Zfr7uVfopc98d1XuMwvZKZg8bAZBxBrpoL9NbGvn9MZa9tEXTmLiLByF4Ixx4Ov4
ugHZIPIgoIRl8L7J9WQ47+oVwASqR86q9QWUNnZCmF+KngjreHz+dhGDLv5I7bFK
tNvgEOcBmIsBgqgmda9pH9HEJhuRXQkXLt9pZwMX+BjQMoTyuIr/xmSX1RPTNuIP
P261yON+J92Wt7V093zI
=x8zB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2331-1
September 02, 2014
libreoffice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
LibreOffice Calc could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- libreoffice: Office productivity suite
Details:
Rohan Durve and James Kettle discovered LibreOffice Calc sometimes allowed
for command injection when opening spreadsheets. If a user were tricked
into opening a crafted Calc spreadsheet, an attacker could exploit this to
run programs as your login.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libreoffice-core 1:4.2.6.3-0ubuntu1
After a standard system update you need to restart LibreOffice to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2331-1
CVE-2014-3524
Package Information:
https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.6.3-0ubuntu1
[USN-2333-1] Linux kernel (EC2) vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgYOAAoJEAUvNnAY1cPYXPsP/15Nt1I2nvlvYZBmYVweGFEV
t+5OGVA1W+F4qXZg3QPoWBzpucK/Q/RHR0jVsyqwy7+oqIaSZkIDWgj0Avp1FhzH
C8Hk5xz/AP/Auf76Tbdhz7XbWKOoEUtIvFUGIUCtMH9xsPutY5xmuYPigmddQdSS
09d2c3+3gpAUQKwPgogQP4uOw48MJD6XbPqgZ0rG9KEm7bzZecfICAe/zhhYlDAW
Bkm5lz9X+eKlmKKClWE9Zdacn4pS97/7wbiC1NheQYalNbuAUUumnoJqA29AzRhQ
HOLi7fLlzLBCz1STn7tfx9+9Nqyn3TEsQ+wAa6LyMTbKEiZur61KIkHnVmsUKN27
M1ayOo58/tyOCArflyRFT8scpakWWTVg0I5bgWk+1osKvDvYgnVyU01KUpreWB00
yVu1qclrfUhZtqYJ9kYEB517T4k3bqspaarOaSSmSztsoruWcmFRUEWz8A2pDLxL
c4j6kzDGUZ9hizTJkfEESnmO7kxjT8Yg95N7I6rWfvKYmaOYGtaYOxCzOnx8giWf
/yBCwyY3WJibMqg74tyJbhujeSwsBZiEdYEhTtSZiczG8p9xSvkwaRLntemyS0jq
z0cElxxXzOFmAQ4/jQ+4nQHwL574AWTukCTOqi1UtfDTEjxfI8K0xMDmkBo/KRm6
MdyuRCFG98SDqLJT/Nup
=AfNT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2333-1
September 02, 2014
linux-ec2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ec2: Linux kernel for EC2
Details:
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-369-ec2 2.6.32-369.85
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2333-1
CVE-2014-0203, CVE-2014-4508, CVE-2014-4652, CVE-2014-4653,
CVE-2014-4654, CVE-2014-4655, CVE-2014-4656, CVE-2014-4667,
CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-369.85
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgYOAAoJEAUvNnAY1cPYXPsP/15Nt1I2nvlvYZBmYVweGFEV
t+5OGVA1W+F4qXZg3QPoWBzpucK/Q/RHR0jVsyqwy7+oqIaSZkIDWgj0Avp1FhzH
C8Hk5xz/AP/Auf76Tbdhz7XbWKOoEUtIvFUGIUCtMH9xsPutY5xmuYPigmddQdSS
09d2c3+3gpAUQKwPgogQP4uOw48MJD6XbPqgZ0rG9KEm7bzZecfICAe/zhhYlDAW
Bkm5lz9X+eKlmKKClWE9Zdacn4pS97/7wbiC1NheQYalNbuAUUumnoJqA29AzRhQ
HOLi7fLlzLBCz1STn7tfx9+9Nqyn3TEsQ+wAa6LyMTbKEiZur61KIkHnVmsUKN27
M1ayOo58/tyOCArflyRFT8scpakWWTVg0I5bgWk+1osKvDvYgnVyU01KUpreWB00
yVu1qclrfUhZtqYJ9kYEB517T4k3bqspaarOaSSmSztsoruWcmFRUEWz8A2pDLxL
c4j6kzDGUZ9hizTJkfEESnmO7kxjT8Yg95N7I6rWfvKYmaOYGtaYOxCzOnx8giWf
/yBCwyY3WJibMqg74tyJbhujeSwsBZiEdYEhTtSZiczG8p9xSvkwaRLntemyS0jq
z0cElxxXzOFmAQ4/jQ+4nQHwL574AWTukCTOqi1UtfDTEjxfI8K0xMDmkBo/KRm6
MdyuRCFG98SDqLJT/Nup
=AfNT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2333-1
September 02, 2014
linux-ec2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux-ec2: Linux kernel for EC2
Details:
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-369-ec2 2.6.32-369.85
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2333-1
CVE-2014-0203, CVE-2014-4508, CVE-2014-4652, CVE-2014-4653,
CVE-2014-4654, CVE-2014-4655, CVE-2014-4656, CVE-2014-4667,
CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-369.85
[USN-2332-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgXrAAoJEAUvNnAY1cPYEVgP/1aYus7yGGrn3YAhFRPy16BQ
+T011Hlya2eNdAkAZeJsTruwPQCAsmFOFICMBus+OwxRyg08H1svRaV9EKxxjAQ9
IV4x/QvEgBmiHL+lGN6w/OGSwVuXRBr+8kpwWjjagOpC9ks9B7Ak9jgk3gP0SZ+j
7YUsOaeZixCkEhWZG2jq3pvprBHu+91gzk5pc5QWRG5FaE2/j9sJO3cGfSuXK46b
4tf3bI8Qnbzkiziau8ETxM596sOoocOayqhCZ98cB5R4wYZDfQhUHs0Np0GuJ1SK
wDeZWFvteLw5QpiJV2JmUQovRdjxPipwURTS6UXykAx9TKruGd40QZypcjai1ym/
YgkXqwPehjhQOch7hx9mawx8ospPd5k41s5rBcD75x9s7F0COsB/7fPO/+39qPaC
p1zc5FbC1Jxjm2rK8Pwks26k9DKLQZ2EayFDgRR7PeHX+eCG8KhvQEo+Go0V+pqj
PMV6cUdpcXLN+iF0abFQix17sNqe1tY90wHf/HEDq3CZAFV99WivwiwiH0FnIwZO
IR4X561DIUpIlyQeqmHjSdW+1QFzYyWxhTzmnVG5sL15jkehgdSqFdRYH8FB34eM
jcbD/ky1cx15ngqL1FJEgVa/sLb29uMWLVBiB9zHMFr5+67y9krTmIV8+t6Cwin7
gK0r5tqsdLFDBkQHfbLp
=m+AX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2332-1
September 02, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-65-386 2.6.32-65.131
linux-image-2.6.32-65-generic 2.6.32-65.131
linux-image-2.6.32-65-generic-pae 2.6.32-65.131
linux-image-2.6.32-65-ia64 2.6.32-65.131
linux-image-2.6.32-65-lpia 2.6.32-65.131
linux-image-2.6.32-65-powerpc 2.6.32-65.131
linux-image-2.6.32-65-powerpc-smp 2.6.32-65.131
linux-image-2.6.32-65-powerpc64-smp 2.6.32-65.131
linux-image-2.6.32-65-preempt 2.6.32-65.131
linux-image-2.6.32-65-server 2.6.32-65.131
linux-image-2.6.32-65-sparc64 2.6.32-65.131
linux-image-2.6.32-65-sparc64-smp 2.6.32-65.131
linux-image-2.6.32-65-versatile 2.6.32-65.131
linux-image-2.6.32-65-virtual 2.6.32-65.131
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2332-1
CVE-2014-0203, CVE-2014-4508, CVE-2014-4652, CVE-2014-4653,
CVE-2014-4654, CVE-2014-4655, CVE-2014-4656, CVE-2014-4667,
CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-65.131
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgXrAAoJEAUvNnAY1cPYEVgP/1aYus7yGGrn3YAhFRPy16BQ
+T011Hlya2eNdAkAZeJsTruwPQCAsmFOFICMBus+OwxRyg08H1svRaV9EKxxjAQ9
IV4x/QvEgBmiHL+lGN6w/OGSwVuXRBr+8kpwWjjagOpC9ks9B7Ak9jgk3gP0SZ+j
7YUsOaeZixCkEhWZG2jq3pvprBHu+91gzk5pc5QWRG5FaE2/j9sJO3cGfSuXK46b
4tf3bI8Qnbzkiziau8ETxM596sOoocOayqhCZ98cB5R4wYZDfQhUHs0Np0GuJ1SK
wDeZWFvteLw5QpiJV2JmUQovRdjxPipwURTS6UXykAx9TKruGd40QZypcjai1ym/
YgkXqwPehjhQOch7hx9mawx8ospPd5k41s5rBcD75x9s7F0COsB/7fPO/+39qPaC
p1zc5FbC1Jxjm2rK8Pwks26k9DKLQZ2EayFDgRR7PeHX+eCG8KhvQEo+Go0V+pqj
PMV6cUdpcXLN+iF0abFQix17sNqe1tY90wHf/HEDq3CZAFV99WivwiwiH0FnIwZO
IR4X561DIUpIlyQeqmHjSdW+1QFzYyWxhTzmnVG5sL15jkehgdSqFdRYH8FB34eM
jcbD/ky1cx15ngqL1FJEgVa/sLb29uMWLVBiB9zHMFr5+67y9krTmIV8+t6Cwin7
gK0r5tqsdLFDBkQHfbLp
=m+AX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2332-1
September 02, 2014
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was discovered in the Advanced Linux Sound
Architecture (ALSA) control implementation of the Linux kernel. A local
user could exploit this flaw to cause a denial of service (system crash).
(CVE-2014-4653)
A authorization bug was discovered with the snd_ctl_elem_add function of
the Advanced Linux Sound Architecture (ALSA) in the Linux kernel. A local
user could exploit his bug to cause a denial of service (remove kernel
controls). (CVE-2014-4654)
A flaw discovered in how the snd_ctl_elem function of the Advanced Linux
Sound Architecture (ALSA) handled a reference count. A local user could
exploit this flaw to cause a denial of service (integer overflow and limit
bypass). (CVE-2014-4655)
An integer overflow flaw was discovered in the control implementation of
the Advanced Linux Sound Architecture (ALSA). A local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2014-4656)
An integer underflow flaw was discovered in the Linux kernel's handling of
the backlog value for certain SCTP packets. A remote attacker could exploit
this flaw to cause a denial of service (socket outage) via a crafted SCTP
packet. (CVE-2014-4667)
Jason Gunthorpe reported a flaw with SCTP authentication in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (NULL pointer dereference and OOPS). (CVE-2014-5077)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
linux-image-2.6.32-65-386 2.6.32-65.131
linux-image-2.6.32-65-generic 2.6.32-65.131
linux-image-2.6.32-65-generic-pae 2.6.32-65.131
linux-image-2.6.32-65-ia64 2.6.32-65.131
linux-image-2.6.32-65-lpia 2.6.32-65.131
linux-image-2.6.32-65-powerpc 2.6.32-65.131
linux-image-2.6.32-65-powerpc-smp 2.6.32-65.131
linux-image-2.6.32-65-powerpc64-smp 2.6.32-65.131
linux-image-2.6.32-65-preempt 2.6.32-65.131
linux-image-2.6.32-65-server 2.6.32-65.131
linux-image-2.6.32-65-sparc64 2.6.32-65.131
linux-image-2.6.32-65-sparc64-smp 2.6.32-65.131
linux-image-2.6.32-65-versatile 2.6.32-65.131
linux-image-2.6.32-65-virtual 2.6.32-65.131
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-2332-1
CVE-2014-0203, CVE-2014-4508, CVE-2014-4652, CVE-2014-4653,
CVE-2014-4654, CVE-2014-4655, CVE-2014-4656, CVE-2014-4667,
CVE-2014-5077
Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-65.131
[USN-2331-1] LibreOffice vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgOhAAoJEFHb3FjMVZVzb7YP/R0w/nJ8MmghMve7HEiLDuOr
vFCE+1BMmWAm+2ERADXzQDbjRyUEIMpUX1+wryuO6ES9MfFhSNXZ736p0SsKJ2CG
/V77Vrm1aFbs0eIf3hl6jfWiV81A0D3GGXNLUHYlgdSqKh2SqMgZNnfcrbLR/T6I
x2pi0Fzunvqmxj8sv6FLXNiHGVqA9KY4MBKSn1UvLBcC1HmTzJvYj/wVIapR5cUf
mi1NiHj9/a/jIBz78aF0SdUb7t6rgxH3y3t0bQ/yFfX74JlkoZAW00OOlVXTMvsH
weO9JiGalGtn2zD+4kqRWTcj29QIJiZelIeuW5b9kaX+q2HdwTievI6z5hE+vDxv
J7+FmYRdJMc5krggCBD5VHzh+wFA3K84DBG26F03jNIRnldT3K9uSn85zfm34jRT
JTYdD9m5GuQ1DkKfDAP0M27kB0obNJbgkwrKZ5BcsTihS+Cj9Vct8qYgD7Nk9NWL
1TZejIywAj+ATCPx0lMYuwcESLeFuEvvSGdHHRI2Ar31OlBdUR5NGmir+HN0LYcB
1Qd8fqKDVhpLhZJG7pMfLjrtMykBekRwi//F/R/MmFGMAESM7aJUvcc7LwKVzidW
dW5MDmi0IbToozyvAu6lMAFQStNLsxMnTUY/rndS92K3R0xhQ7/ya5b7FRb7YvRW
En/JneyWc3ijLgEQxwos
=kzyg
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2331-1
September 02, 2014
libreoffice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
LibreOffice Calc could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- libreoffice: Office productivity suite
Details:
Rohan Durve and James Kettle discovered LibreOffice Calc sometimes allowed
for command injection when opening spreadsheets. If a user were tricked
into opening a crafted Calc spreadsheet, an attacker could exploit this to
run programs as your login.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libreoffice-core 1:4.2.6.3-0ubuntu1
After a standard system update you need to restart LibreOffice to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2331-1
CVE-2014-3524
Package Information:
https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.6.3-0ubuntu1
Version: GnuPG v1
iQIcBAEBCgAGBQJUBgOhAAoJEFHb3FjMVZVzb7YP/R0w/nJ8MmghMve7HEiLDuOr
vFCE+1BMmWAm+2ERADXzQDbjRyUEIMpUX1+wryuO6ES9MfFhSNXZ736p0SsKJ2CG
/V77Vrm1aFbs0eIf3hl6jfWiV81A0D3GGXNLUHYlgdSqKh2SqMgZNnfcrbLR/T6I
x2pi0Fzunvqmxj8sv6FLXNiHGVqA9KY4MBKSn1UvLBcC1HmTzJvYj/wVIapR5cUf
mi1NiHj9/a/jIBz78aF0SdUb7t6rgxH3y3t0bQ/yFfX74JlkoZAW00OOlVXTMvsH
weO9JiGalGtn2zD+4kqRWTcj29QIJiZelIeuW5b9kaX+q2HdwTievI6z5hE+vDxv
J7+FmYRdJMc5krggCBD5VHzh+wFA3K84DBG26F03jNIRnldT3K9uSn85zfm34jRT
JTYdD9m5GuQ1DkKfDAP0M27kB0obNJbgkwrKZ5BcsTihS+Cj9Vct8qYgD7Nk9NWL
1TZejIywAj+ATCPx0lMYuwcESLeFuEvvSGdHHRI2Ar31OlBdUR5NGmir+HN0LYcB
1Qd8fqKDVhpLhZJG7pMfLjrtMykBekRwi//F/R/MmFGMAESM7aJUvcc7LwKVzidW
dW5MDmi0IbToozyvAu6lMAFQStNLsxMnTUY/rndS92K3R0xhQ7/ya5b7FRb7YvRW
En/JneyWc3ijLgEQxwos
=kzyg
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2331-1
September 02, 2014
libreoffice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
LibreOffice Calc could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- libreoffice: Office productivity suite
Details:
Rohan Durve and James Kettle discovered LibreOffice Calc sometimes allowed
for command injection when opening spreadsheets. If a user were tricked
into opening a crafted Calc spreadsheet, an attacker could exploit this to
run programs as your login.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libreoffice-core 1:4.2.6.3-0ubuntu1
After a standard system update you need to restart LibreOffice to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2331-1
CVE-2014-3524
Package Information:
https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.6.3-0ubuntu1
Dear reallost1.fbsd2233449
reallost1.fbsd2233449 亲!
附件中的内容打造金牌店长特训营,希望能帮助到贵公司的发展。
yshsfc-
祝您工作顺利,身体健康
房南元1:39:04
Subscribe to:
Posts (Atom)