-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSaDS9AAoJEFHb3FjMVZVzrNAQAKLQHzNZKT1n/kjZArSNURrg
KBQ87s47KyXWTrxMNAHQTsiRetOBpT8NO77lyPQLcf7AO6PH1xkmy0T3+EAwMLLd
A00AE0Ye/t1FpN0Atkxt+1+xoVCAJuOW3v70u57hmr5TKbBJ0zGAzN23eJhmIVl/
KMkvM5YhAYFYRaLYlak727Spo9auMmB/KBmNXpC/AhzRTC2XCKacPxdTrH8Zoqib
pk4mi3d3im1yRtT/hm83KsNGyVwcbAtFB4kZlP49TYjLdMoFlXdnRhnRnHZlVSru
nUD3jAKH2/Yn8SP4dEcT9KEs+MtkEduA4PvdsSbWi1ri2bu+dIlz6O8Rlt6hjPdN
PwpejQykur/vYBijKYrFuqpWIq+X4beFu+F0zpG2HvN1UGGszVchoepemoOVHg6U
16KKgRksKNM23ZMezqfyPC+TKdoTiZpnIBBW+xvPt0PKm+fjw9V+W7fpB5K2M+yS
oKI1G50S2CF0cguTTYvw1w9peliTpSr/W9eoNISaR8YR0tPOc/PD9Fl0LT8fPWWw
mH/yRP6jW9EraD6roDyLalY+S9KFg6QFIyjVpsS9aq7JA0ZJmfKdC3/8sA7Qk/u9
IXEB44hos9qq4EBa4cMDCguKnICj1jQitYszSxpP94EKyqWRue1qV0nLw4V18Yub
7IyqbKiTlb5kEdiXlR7L
=N76K
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2000-1
October 23, 2013
nova vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Nova could be made to crash if it received specially crafted network
requests.
Software Description:
- nova: OpenStack Compute cloud infrastructure
Details:
It was discovered that Nova did not properly enforce the is_public property
when determining flavor access. An authenticated attacker could exploit
this to obtain sensitive information in private flavors. This issue only
affected Ubuntu 12.10 and 13.10. (CVE-2013-2256, CVE-2013-4278)
Grant Murphy discovered that Nova would allow XML entity processing. A
remote unauthenticated attacker could exploit this using the Nova API to
cause a denial of service via resource exhaustion. This issue only
affected Ubuntu 13.10. (CVE-2013-4179)
Vishvananda Ishaya discovered that Nova inefficiently handled network
security group updates when Nova was configured to use nova-network. An
authenticated attacker could exploit this to cause a denial of service.
(CVE-2013-4185)
Jaroslav Henner discovered that Nova did not properly handle certain inputs
to the instance console when Nova was configured to use Apache Qpid. An
authenticated attacker could exploit this to cause a denial of service on
the compute node running the instance. By default, Ubuntu uses RabbitMQ
instead of Qpid. (CVE-2013-4261)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
python-nova 1:2013.1.3-0ubuntu1.1
Ubuntu 12.10:
python-nova 2012.2.4-0ubuntu3.1
Ubuntu 12.04 LTS:
python-nova 2012.1.3+stable-20130423-e52e6912-0ubuntu1.2
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2000-1
CVE-2013-2256, CVE-2013-4179, CVE-2013-4185, CVE-2013-4261,
CVE-2013-4278
Package Information:
https://launchpad.net/ubuntu/+source/nova/1:2013.1.3-0ubuntu1.1
https://launchpad.net/ubuntu/+source/nova/2012.2.4-0ubuntu3.1
https://launchpad.net/ubuntu/+source/nova/2012.1.3+stable-20130423-e52e6912-0ubuntu1.2
Wednesday, October 23, 2013
[USN-2001-1] Swift vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSaDSUAAoJEFHb3FjMVZVzN+sQAJVRjhexc+vVKV1A4h5quKxP
RQvPue6g82ZTDDI5dqRdeDiD6lsjR1x9hzmssbBtYEdcAFxB8N+wpw5zvLKxJddd
gL9HMdxemwrYSfC88r5Z8+virOcG22tKUMaMHhut3gz3u8WPUc4htOPzqTLPRC4E
3Hg5uw3++TNuyaBmPrGWYkV08cqBYNZbkX8diAGmYCc/LaRoggN44PHCScmqYYUI
qDQOJTl+Z9q/r73h46zIxjl0Gt5HD3vxHtDg4IcrFadj2JlcM/XlHea1T86X1KmT
LnAxA0OlwuQVkAk2L6R7BAu28vbUXxmo448SS7V1rcht0okqvRLeTuvBCUBz2q3X
rpFVvkg7bxBehOpEKV3o4gyHSM9Vxuz6Duw69DhiMkr6LNaxEU7akb+qUyOIowUd
aKKL/FzKW4cYsBuEBB6Nfv3UaHAyXS0IF+gPsTTF7yucwMI3BOxVTN0YtavkxVgv
pHsNOJr2gXHM9PTKaK2v0newAEF1bSOBF6kQ19LZlYOh4ShHWRdX8SjIN8h5Z0ut
lKMm3lK0nxKoIlG3Ebfya0VjXvVibyJsVFoqitubCe6KGVsBSgo1S4a+4gkhpCv8
4TjfiMUGIgYdd4h35auzPcdZsbljmv7TvevqeO1zXJj9FHBoxzBXBUVFYm9Q9mpT
J9lKHdMHM6Wjk41XjlsU
=RSCF
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2001-1
October 23, 2013
swift vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Swift could cause the system to crash if it received specially crafted
requests over the network.
Software Description:
- swift: OpenStack distributed virtual object store
Details:
Peter Portante discovered that Swift did not properly handle requests with
old X-Timestamp values. An authenticated attacker could exploit this to
cause a denial of service via disk consumption.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
python-swift 1.8.0-0ubuntu1.3
Ubuntu 12.10:
python-swift 1.7.4-0ubuntu2.3
Ubuntu 12.04 LTS:
python-swift 1.4.8-0ubuntu2.3
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2001-1
CVE-2013-4155
Package Information:
https://launchpad.net/ubuntu/+source/swift/1.8.0-0ubuntu1.3
https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.3
https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.3
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSaDSUAAoJEFHb3FjMVZVzN+sQAJVRjhexc+vVKV1A4h5quKxP
RQvPue6g82ZTDDI5dqRdeDiD6lsjR1x9hzmssbBtYEdcAFxB8N+wpw5zvLKxJddd
gL9HMdxemwrYSfC88r5Z8+virOcG22tKUMaMHhut3gz3u8WPUc4htOPzqTLPRC4E
3Hg5uw3++TNuyaBmPrGWYkV08cqBYNZbkX8diAGmYCc/LaRoggN44PHCScmqYYUI
qDQOJTl+Z9q/r73h46zIxjl0Gt5HD3vxHtDg4IcrFadj2JlcM/XlHea1T86X1KmT
LnAxA0OlwuQVkAk2L6R7BAu28vbUXxmo448SS7V1rcht0okqvRLeTuvBCUBz2q3X
rpFVvkg7bxBehOpEKV3o4gyHSM9Vxuz6Duw69DhiMkr6LNaxEU7akb+qUyOIowUd
aKKL/FzKW4cYsBuEBB6Nfv3UaHAyXS0IF+gPsTTF7yucwMI3BOxVTN0YtavkxVgv
pHsNOJr2gXHM9PTKaK2v0newAEF1bSOBF6kQ19LZlYOh4ShHWRdX8SjIN8h5Z0ut
lKMm3lK0nxKoIlG3Ebfya0VjXvVibyJsVFoqitubCe6KGVsBSgo1S4a+4gkhpCv8
4TjfiMUGIgYdd4h35auzPcdZsbljmv7TvevqeO1zXJj9FHBoxzBXBUVFYm9Q9mpT
J9lKHdMHM6Wjk41XjlsU
=RSCF
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2001-1
October 23, 2013
swift vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Swift could cause the system to crash if it received specially crafted
requests over the network.
Software Description:
- swift: OpenStack distributed virtual object store
Details:
Peter Portante discovered that Swift did not properly handle requests with
old X-Timestamp values. An authenticated attacker could exploit this to
cause a denial of service via disk consumption.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
python-swift 1.8.0-0ubuntu1.3
Ubuntu 12.10:
python-swift 1.7.4-0ubuntu2.3
Ubuntu 12.04 LTS:
python-swift 1.4.8-0ubuntu2.3
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2001-1
CVE-2013-4155
Package Information:
https://launchpad.net/ubuntu/+source/swift/1.8.0-0ubuntu1.3
https://launchpad.net/ubuntu/+source/swift/1.7.4-0ubuntu2.3
https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.3
[CentOS-announce] CEBA-2013:1445 CentOS 6 luci Update
CentOS Errata and Bugfix Advisory 2013:1445
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1445.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
c67604083fcc891846d95ea01f9460d3d3cf047ba9704d59b14a9e9b2d9db889 luci-0.26.0-37.el6.centos.1.i686.rpm
x86_64:
816504bfd75b9cded16ab180d0d23c7c98cc315ea643ab7cb068a61751ea6cf3 luci-0.26.0-37.el6.centos.1.x86_64.rpm
Source:
4467c59799221052bddd487deb033021feb60c0965a3b8e44ef3557d0dec94d1 luci-0.26.0-37.el6.centos.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1445.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
c67604083fcc891846d95ea01f9460d3d3cf047ba9704d59b14a9e9b2d9db889 luci-0.26.0-37.el6.centos.1.i686.rpm
x86_64:
816504bfd75b9cded16ab180d0d23c7c98cc315ea643ab7cb068a61751ea6cf3 luci-0.26.0-37.el6.centos.1.x86_64.rpm
Source:
4467c59799221052bddd487deb033021feb60c0965a3b8e44ef3557d0dec94d1 luci-0.26.0-37.el6.centos.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2013:1451 Critical CentOS 6 java-1.7.0-openjdk Update
CentOS Errata and Security Advisory 2013:1451 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1451.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0523ba78e4cb655ee6ef84ae0917fbe8519c30b8532c7996643741668f33c81f java-1.7.0-openjdk-1.7.0.45-2.4.3.2.el6_4.i686.rpm
7d465b4b2a4ef62fdad058fbd00cb9408b3d2157419791e81a52086dedc7cddd java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.2.el6_4.i686.rpm
a7c8e25597c033da02556c2e22b730868131e6fd06d1351c4ea530e7bf60ebf3 java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.2.el6_4.i686.rpm
ba19e6bbceb0deaaf83905c277063a0461d9c49c8a54a41e6b05419cdb93c0aa java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.2.el6_4.noarch.rpm
6be4013c68bc6d46d40b50e4d4fcc045e40942a3e3e2edc7ce08aa2b31819f32 java-1.7.0-openjdk-src-1.7.0.45-2.4.3.2.el6_4.i686.rpm
x86_64:
d6e36e9d2be2d87cce5e89abb5d6bd092a8fb8c7a76f4259759502e434f50f46 java-1.7.0-openjdk-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
9f29e741889cb9d9a343c5164d99e5cdf53b1213ac278b91dd736979433991c3 java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
b58786643115a9805f2c4a4446423491bab782b96ea663c032fc2a261ab11362 java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
ba19e6bbceb0deaaf83905c277063a0461d9c49c8a54a41e6b05419cdb93c0aa java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.2.el6_4.noarch.rpm
41793ba357142d47aa012374949d97a3c265a7009c1f10fb217dedd3ad370367 java-1.7.0-openjdk-src-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
Source:
5e43e18e1ef6b40bb49db615ca98c0b453ec1418a0175ce102a2f13af693ef82 java-1.7.0-openjdk-1.7.0.45-2.4.3.2.el6_4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1451.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0523ba78e4cb655ee6ef84ae0917fbe8519c30b8532c7996643741668f33c81f java-1.7.0-openjdk-1.7.0.45-2.4.3.2.el6_4.i686.rpm
7d465b4b2a4ef62fdad058fbd00cb9408b3d2157419791e81a52086dedc7cddd java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.2.el6_4.i686.rpm
a7c8e25597c033da02556c2e22b730868131e6fd06d1351c4ea530e7bf60ebf3 java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.2.el6_4.i686.rpm
ba19e6bbceb0deaaf83905c277063a0461d9c49c8a54a41e6b05419cdb93c0aa java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.2.el6_4.noarch.rpm
6be4013c68bc6d46d40b50e4d4fcc045e40942a3e3e2edc7ce08aa2b31819f32 java-1.7.0-openjdk-src-1.7.0.45-2.4.3.2.el6_4.i686.rpm
x86_64:
d6e36e9d2be2d87cce5e89abb5d6bd092a8fb8c7a76f4259759502e434f50f46 java-1.7.0-openjdk-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
9f29e741889cb9d9a343c5164d99e5cdf53b1213ac278b91dd736979433991c3 java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
b58786643115a9805f2c4a4446423491bab782b96ea663c032fc2a261ab11362 java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
ba19e6bbceb0deaaf83905c277063a0461d9c49c8a54a41e6b05419cdb93c0aa java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.2.el6_4.noarch.rpm
41793ba357142d47aa012374949d97a3c265a7009c1f10fb217dedd3ad370367 java-1.7.0-openjdk-src-1.7.0.45-2.4.3.2.el6_4.x86_64.rpm
Source:
5e43e18e1ef6b40bb49db615ca98c0b453ec1418a0175ce102a2f13af693ef82 java-1.7.0-openjdk-1.7.0.45-2.4.3.2.el6_4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2013:1452 Moderate CentOS 6 vino Update
CentOS Errata and Security Advisory 2013:1452 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1452.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
ba60630e41e8c8341218d49294c94402ad59e251f1e4ef5b458aa2da7fc160cc vino-2.28.1-9.el6_4.i686.rpm
x86_64:
ae504fcc0bc39310b018c480d8bd35ca3e7b1e6bb0dfc7d3b94b6d7adb7e7978 vino-2.28.1-9.el6_4.x86_64.rpm
Source:
9d2b7f9631575b713aa33def772c33fbb5a0bab882912464b47c9f7ba35d6f0b vino-2.28.1-9.el6_4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1452.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
ba60630e41e8c8341218d49294c94402ad59e251f1e4ef5b458aa2da7fc160cc vino-2.28.1-9.el6_4.i686.rpm
x86_64:
ae504fcc0bc39310b018c480d8bd35ca3e7b1e6bb0dfc7d3b94b6d7adb7e7978 vino-2.28.1-9.el6_4.x86_64.rpm
Source:
9d2b7f9631575b713aa33def772c33fbb5a0bab882912464b47c9f7ba35d6f0b vino-2.28.1-9.el6_4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2013:1446 CentOS 6 mdadm Update
CentOS Errata and Bugfix Advisory 2013:1446
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1446.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f4661f0efa2d95e39b4dfde5ceef7513f8bcdfebe063a28d5e087f1fbf9a8ac1 mdadm-3.2.5-4.el6_4.3.i686.rpm
x86_64:
a4d26721eeeae7cc403a91dbac6f12ce0488a8f2858bfb18167b6907763b4c12 mdadm-3.2.5-4.el6_4.3.x86_64.rpm
Source:
39ac296e7a8d96e476bce2296e04084d606ef7fdc8ebe6c14eefff629188aca1 mdadm-3.2.5-4.el6_4.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1446.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
f4661f0efa2d95e39b4dfde5ceef7513f8bcdfebe063a28d5e087f1fbf9a8ac1 mdadm-3.2.5-4.el6_4.3.i686.rpm
x86_64:
a4d26721eeeae7cc403a91dbac6f12ce0488a8f2858bfb18167b6907763b4c12 mdadm-3.2.5-4.el6_4.3.x86_64.rpm
Source:
39ac296e7a8d96e476bce2296e04084d606ef7fdc8ebe6c14eefff629188aca1 mdadm-3.2.5-4.el6_4.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2013:1452 Moderate CentOS 5 vino Update
CentOS Errata and Security Advisory 2013:1452 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1452.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
6f9e41d0b9e7dc36736a76d4e13e637faade333740eb51478580177461b631f7 vino-2.13.5-10.el5_10.i386.rpm
x86_64:
8e7bfa8d07c76eaa42d77c6e7b8433c500c9057e4b4b734c8e0bea9627c9eb98 vino-2.13.5-10.el5_10.x86_64.rpm
Source:
0b551da8a6bc208b7a764a224fd279ef10bdd74822b0a6694c6700c4c6f25096 vino-2.13.5-10.el5_10.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1452.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
6f9e41d0b9e7dc36736a76d4e13e637faade333740eb51478580177461b631f7 vino-2.13.5-10.el5_10.i386.rpm
x86_64:
8e7bfa8d07c76eaa42d77c6e7b8433c500c9057e4b4b734c8e0bea9627c9eb98 vino-2.13.5-10.el5_10.x86_64.rpm
Source:
0b551da8a6bc208b7a764a224fd279ef10bdd74822b0a6694c6700c4c6f25096 vino-2.13.5-10.el5_10.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Tuesday, October 22, 2013
[CentOS-announce] CESA-2013:1449 Moderate CentOS 5 kernel Update
CentOS Errata and Security Advisory 2013:1449 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1449.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
a4d3216439de530d2468961c4a61ce5cbd220ebad5dac650e5bc8944ec11d0dc kernel-2.6.18-371.1.2.el5.i686.rpm
58af2179222547220a1d40b1590fd0db4e68a02700035c4ca3bcf9e2142c86e2 kernel-debug-2.6.18-371.1.2.el5.i686.rpm
b92031e1a4a0f30ccc45704e9a2446a5ab1fb32c2f0ae69bc727beb1630b38c0 kernel-debug-devel-2.6.18-371.1.2.el5.i686.rpm
1ce6934b4070ee9520b04758109c92ffe172b54d46a4428225872fdf92796641 kernel-devel-2.6.18-371.1.2.el5.i686.rpm
b37c616c9fa11bd497f1b5ddbf044a334920a50c9196c9cc7b65c6becc29a02d kernel-doc-2.6.18-371.1.2.el5.noarch.rpm
b63b5db3d7ad97682afc0ed8d2f84c2d17259bd5b99a4381ea3ac36aa32629e4 kernel-headers-2.6.18-371.1.2.el5.i386.rpm
eb76cfbe693caf4ec576b5a8a454c7ab5f696c5f1cb8c58751dc206d0890ff3c kernel-PAE-2.6.18-371.1.2.el5.i686.rpm
fd8545968ea1dd6709019efdbcd420c35d8a9e3c4dbb97d68b71c7c8f53b2fcb kernel-PAE-devel-2.6.18-371.1.2.el5.i686.rpm
bf8dde7ca686728b2baa43fe60977cec426afb53d292aae63fab301b54cb7e58 kernel-xen-2.6.18-371.1.2.el5.i686.rpm
c8aed1fe661a60ceca8a4f7ab424f0e04a0b3d4e045607a9fede066d845c2eca kernel-xen-devel-2.6.18-371.1.2.el5.i686.rpm
x86_64:
fab32fb436d0476f3653c7383514016fc2c216a4553a4b3e0c5ccd1d4c7b4318 kernel-2.6.18-371.1.2.el5.x86_64.rpm
a5edb60b2c187cd68e226a75287f59f3a58a3c7c060031f1ed37f1c197340bea kernel-debug-2.6.18-371.1.2.el5.x86_64.rpm
8be7b0c728784683340b06c6b6143a97f8b30563fa01f7f665f569c88627301c kernel-debug-devel-2.6.18-371.1.2.el5.x86_64.rpm
72693349bc251745f015964df7be327d1ade06cb5b8a1574f67559b64706e5d6 kernel-devel-2.6.18-371.1.2.el5.x86_64.rpm
b37c616c9fa11bd497f1b5ddbf044a334920a50c9196c9cc7b65c6becc29a02d kernel-doc-2.6.18-371.1.2.el5.noarch.rpm
cd6ac0b3b3dcd547e5277094fa5b1d33df38fca0be6790ed270c2cb58e00144c kernel-headers-2.6.18-371.1.2.el5.x86_64.rpm
97a73c420767c33c3d0aefbf5af46ca0a88fa41b071bbb153bbad44b03e49d93 kernel-xen-2.6.18-371.1.2.el5.x86_64.rpm
4a51b3b08a85cab68bed2ee0e60ccd45ed367c31ef58419dc3864c0548baf9ed kernel-xen-devel-2.6.18-371.1.2.el5.x86_64.rpm
Source:
fc5d4b1ef85ad875a112bffd8c4581ed5a2dce0beb0b3adcde5f0de652bef1c7 kernel-2.6.18-371.1.2.el5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1449.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
a4d3216439de530d2468961c4a61ce5cbd220ebad5dac650e5bc8944ec11d0dc kernel-2.6.18-371.1.2.el5.i686.rpm
58af2179222547220a1d40b1590fd0db4e68a02700035c4ca3bcf9e2142c86e2 kernel-debug-2.6.18-371.1.2.el5.i686.rpm
b92031e1a4a0f30ccc45704e9a2446a5ab1fb32c2f0ae69bc727beb1630b38c0 kernel-debug-devel-2.6.18-371.1.2.el5.i686.rpm
1ce6934b4070ee9520b04758109c92ffe172b54d46a4428225872fdf92796641 kernel-devel-2.6.18-371.1.2.el5.i686.rpm
b37c616c9fa11bd497f1b5ddbf044a334920a50c9196c9cc7b65c6becc29a02d kernel-doc-2.6.18-371.1.2.el5.noarch.rpm
b63b5db3d7ad97682afc0ed8d2f84c2d17259bd5b99a4381ea3ac36aa32629e4 kernel-headers-2.6.18-371.1.2.el5.i386.rpm
eb76cfbe693caf4ec576b5a8a454c7ab5f696c5f1cb8c58751dc206d0890ff3c kernel-PAE-2.6.18-371.1.2.el5.i686.rpm
fd8545968ea1dd6709019efdbcd420c35d8a9e3c4dbb97d68b71c7c8f53b2fcb kernel-PAE-devel-2.6.18-371.1.2.el5.i686.rpm
bf8dde7ca686728b2baa43fe60977cec426afb53d292aae63fab301b54cb7e58 kernel-xen-2.6.18-371.1.2.el5.i686.rpm
c8aed1fe661a60ceca8a4f7ab424f0e04a0b3d4e045607a9fede066d845c2eca kernel-xen-devel-2.6.18-371.1.2.el5.i686.rpm
x86_64:
fab32fb436d0476f3653c7383514016fc2c216a4553a4b3e0c5ccd1d4c7b4318 kernel-2.6.18-371.1.2.el5.x86_64.rpm
a5edb60b2c187cd68e226a75287f59f3a58a3c7c060031f1ed37f1c197340bea kernel-debug-2.6.18-371.1.2.el5.x86_64.rpm
8be7b0c728784683340b06c6b6143a97f8b30563fa01f7f665f569c88627301c kernel-debug-devel-2.6.18-371.1.2.el5.x86_64.rpm
72693349bc251745f015964df7be327d1ade06cb5b8a1574f67559b64706e5d6 kernel-devel-2.6.18-371.1.2.el5.x86_64.rpm
b37c616c9fa11bd497f1b5ddbf044a334920a50c9196c9cc7b65c6becc29a02d kernel-doc-2.6.18-371.1.2.el5.noarch.rpm
cd6ac0b3b3dcd547e5277094fa5b1d33df38fca0be6790ed270c2cb58e00144c kernel-headers-2.6.18-371.1.2.el5.x86_64.rpm
97a73c420767c33c3d0aefbf5af46ca0a88fa41b071bbb153bbad44b03e49d93 kernel-xen-2.6.18-371.1.2.el5.x86_64.rpm
4a51b3b08a85cab68bed2ee0e60ccd45ed367c31ef58419dc3864c0548baf9ed kernel-xen-devel-2.6.18-371.1.2.el5.x86_64.rpm
Source:
fc5d4b1ef85ad875a112bffd8c4581ed5a2dce0beb0b3adcde5f0de652bef1c7 kernel-2.6.18-371.1.2.el5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2013:1447 Important CentOS 5 java-1.7.0-openjdk Update
CentOS Errata and Security Advisory 2013:1447 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1447.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
fb118d428dac9add2e94bde4f61e13c4a795079a1579c3e875ab0b50a9482a06 java-1.7.0-openjdk-1.7.0.45-2.4.3.1.el5_10.i386.rpm
22fa5e6cc950f326aa97ab39b5afa29a5ff381ab628b54c11722c9a955feab2d java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.1.el5_10.i386.rpm
671774e11385e6d2a48b4404396f4aa10ed1fb1e2ba2169bbc5285b13fb6083f java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.1.el5_10.i386.rpm
d52f06e0db180855025068c5bd82d6cf0de711405b15bf3e7d370725355fd7b3 java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.1.el5_10.i386.rpm
beb4cb7825621519fbb31246a68b02b7a3ce97756a111463fcc4c316bc3d3f8c java-1.7.0-openjdk-src-1.7.0.45-2.4.3.1.el5_10.i386.rpm
x86_64:
591b8dcdc1295536cbd692b7b420787774645600409926050915d9b04e594f8e java-1.7.0-openjdk-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
5ea0df10f435a54548ba4537c246407f065a1d7af6e550b6657cd3450e671405 java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
ee3ce55ada00a909bd512bfc63b8b8e217da9007b5707ff2f8a70054f736ed32 java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
f224698988353e0b11eb174e0a850f577a8542c27026fb255621bb93026f84ea java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
dc36c44b883491715f46af01054727a2becd755ad9402de76402a32c74ee1280 java-1.7.0-openjdk-src-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
Source:
2f33521ebb7211a1d0afba63747604697e0d6061c8962aee72cff1bfc0ff71de java-1.7.0-openjdk-1.7.0.45-2.4.3.1.el5_10.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1447.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
fb118d428dac9add2e94bde4f61e13c4a795079a1579c3e875ab0b50a9482a06 java-1.7.0-openjdk-1.7.0.45-2.4.3.1.el5_10.i386.rpm
22fa5e6cc950f326aa97ab39b5afa29a5ff381ab628b54c11722c9a955feab2d java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.1.el5_10.i386.rpm
671774e11385e6d2a48b4404396f4aa10ed1fb1e2ba2169bbc5285b13fb6083f java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.1.el5_10.i386.rpm
d52f06e0db180855025068c5bd82d6cf0de711405b15bf3e7d370725355fd7b3 java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.1.el5_10.i386.rpm
beb4cb7825621519fbb31246a68b02b7a3ce97756a111463fcc4c316bc3d3f8c java-1.7.0-openjdk-src-1.7.0.45-2.4.3.1.el5_10.i386.rpm
x86_64:
591b8dcdc1295536cbd692b7b420787774645600409926050915d9b04e594f8e java-1.7.0-openjdk-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
5ea0df10f435a54548ba4537c246407f065a1d7af6e550b6657cd3450e671405 java-1.7.0-openjdk-demo-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
ee3ce55ada00a909bd512bfc63b8b8e217da9007b5707ff2f8a70054f736ed32 java-1.7.0-openjdk-devel-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
f224698988353e0b11eb174e0a850f577a8542c27026fb255621bb93026f84ea java-1.7.0-openjdk-javadoc-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
dc36c44b883491715f46af01054727a2becd755ad9402de76402a32c74ee1280 java-1.7.0-openjdk-src-1.7.0.45-2.4.3.1.el5_10.x86_64.rpm
Source:
2f33521ebb7211a1d0afba63747604697e0d6061c8962aee72cff1bfc0ff71de java-1.7.0-openjdk-1.7.0.45-2.4.3.1.el5_10.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[USN-1999-1] Linux kernel (OMAP4) vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSZgl6AAoJEAUvNnAY1cPYpugP/0Ec2SE7LiXiPLXym/6PPg33
Azb/fazgJU4qMxQROBRjyk0QVxjPAitcRoT0WKbfzfjQar1+LPjKdfF2wlPPaMI1
EUj94wVs7M2M1mtCc2PAJMTnr3++27TOhthon2sU0yNHqqVNPS61XfDy5bN4tBGS
pkLaPdDxsjgKOQFyTkKUtr7Y+Dav2k01xvDkRTJNeHIYimJPtgKQ+aUISJDNpmSk
vpKGJNu0gZIFiN94F3tq5hRj/M8PScJDLD6D/c7C2xEdJjA344je9or16wipE9Y/
OmcjbChcCF5jCdc+L87YUkAc3W395ZZH/nl1JYnTnomJ+8We+ljeLgY7JUb8W3I4
5hc0HBEKtAGL1O+iGfVFgmGozagmgYM/zWpIvrEaJH7PHYYwiTPmDfjOAOxHIwoX
KvreTCjWvAzcUxC++cdZ+/VQyAsi90Hvk786Zx+XhDR9bbVqwNrwqxitYzB8w9yl
W+he2NYicFOM++Lu9uowxV/TG4k2u8sPQsJq5y2ddoa0OId2zYg4ACtSFt9YSADH
seQPt6d6b7Qrh8APrbR1GVuvVOAa0cPSIlhZdFtjpwaMKzEtUz778N/vh/qsauGo
kaMuFncDOALzqhE9yB/QCj+0de0Pa3mt+5xYfszOYFeoPunhtr9hzzVXklkWdrET
zZQtItOlcz8f9qS1EeYb
=E7pS
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1999-1
October 22, 2013
linux-ti-omap4 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
Summary:
The system could be made to expose sensitive information to a local user.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
linux-image-3.5.0-234-omap4 3.5.0-234.50
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-1999-1
CVE-2013-2147
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-234.50
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSZgl6AAoJEAUvNnAY1cPYpugP/0Ec2SE7LiXiPLXym/6PPg33
Azb/fazgJU4qMxQROBRjyk0QVxjPAitcRoT0WKbfzfjQar1+LPjKdfF2wlPPaMI1
EUj94wVs7M2M1mtCc2PAJMTnr3++27TOhthon2sU0yNHqqVNPS61XfDy5bN4tBGS
pkLaPdDxsjgKOQFyTkKUtr7Y+Dav2k01xvDkRTJNeHIYimJPtgKQ+aUISJDNpmSk
vpKGJNu0gZIFiN94F3tq5hRj/M8PScJDLD6D/c7C2xEdJjA344je9or16wipE9Y/
OmcjbChcCF5jCdc+L87YUkAc3W395ZZH/nl1JYnTnomJ+8We+ljeLgY7JUb8W3I4
5hc0HBEKtAGL1O+iGfVFgmGozagmgYM/zWpIvrEaJH7PHYYwiTPmDfjOAOxHIwoX
KvreTCjWvAzcUxC++cdZ+/VQyAsi90Hvk786Zx+XhDR9bbVqwNrwqxitYzB8w9yl
W+he2NYicFOM++Lu9uowxV/TG4k2u8sPQsJq5y2ddoa0OId2zYg4ACtSFt9YSADH
seQPt6d6b7Qrh8APrbR1GVuvVOAa0cPSIlhZdFtjpwaMKzEtUz778N/vh/qsauGo
kaMuFncDOALzqhE9yB/QCj+0de0Pa3mt+5xYfszOYFeoPunhtr9hzzVXklkWdrET
zZQtItOlcz8f9qS1EeYb
=E7pS
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1999-1
October 22, 2013
linux-ti-omap4 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
Summary:
The system could be made to expose sensitive information to a local user.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
linux-image-3.5.0-234-omap4 3.5.0-234.50
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-1999-1
CVE-2013-2147
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-234.50
Monday, October 21, 2013
[USN-1998-1] Linux kernel vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSZgAPAAoJEAUvNnAY1cPYPeYP/i1IbN//W8Ed4srNNMu+vW0J
ABB8HyfI1YEmvpMaQhVjI8NINDT5ZDUsQ6FHPb76v+mzvzeRiE8n2u1XGGcNeLFO
nKwFa8rBNuuJJ0NnM8wMqS+ig9Q00wHPfNwQiMzEb29lq2G4Zufy/J3RfwpnqkEU
ePMrw3KqkEjptG8R8ak4z6tDfaVkptFoIJYqymhilbVNioadUT1SJsBboVfutrs7
tBLvzn78c+3YOZGK7Iicy1pi9BM+fZcK6G/jiyj3rJNqFM7RlKsIIkdhX+Ktfzza
IDA3DB3/gOAC461P9zZUYGGl/CwSsRnQBYSyjz1QCnn7FF6LOiwsIKr4hQqQ2uQ2
ea2St9twP+kEREeDcyg9rq/43xAZflw0QowdO5/gYBulYyyoPzZswIPXOAKDx96g
gUIJMTfo2pRDD1jQK/2A1dN6TtiCw8X1+ITuIT2oB8MBYCYbmngBzdpKyADiTV/W
mJkGveKyL99qH+GZp8EDSCAVYX+IjH7gsUxVQnoHqpBbVbvUgpp44+1sAOYK9prq
1exspMhC+oPd4ICfNYv4XCQLnPAwDWpOePEFP4zBpwVkLufWvz5hcipmk1cebSmP
SHfqRtQKE5VsPNTfrt7DH+AUsB/Aj8LtGprLadVQJAR4TgYzuEoKJsdKoe3Em+b6
h1Fcpkc+w+4QtGQXciCl
=FOo8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1998-1
October 22, 2013
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive information in kernel memory. (CVE-2013-2237)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)
Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)
Kees Cook discovered an information leak in the Linux kernel's Human
Interface Device (HID) subsystem when CONFIG_HID_SENSOR_HUB is enabled. A
physically proximate attacker could obtain potentially sensitive
information from kernel memory via a specially crafted device.
(CVE-2013-2898)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)
A flaw was discovered in how the Linux Kernel's networking stack checks scm
credentials when used with namespaces. A local attacker could exploit this
flaw to gain privileges. (CVE-2013-4300)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
linux-image-3.8.0-32-generic 3.8.0-32.47
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-1998-1
CVE-2013-2237, CVE-2013-2888, CVE-2013-2892, CVE-2013-2896,
CVE-2013-2898, CVE-2013-2899, CVE-2013-4300
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.8.0-32.47
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSZgAPAAoJEAUvNnAY1cPYPeYP/i1IbN//W8Ed4srNNMu+vW0J
ABB8HyfI1YEmvpMaQhVjI8NINDT5ZDUsQ6FHPb76v+mzvzeRiE8n2u1XGGcNeLFO
nKwFa8rBNuuJJ0NnM8wMqS+ig9Q00wHPfNwQiMzEb29lq2G4Zufy/J3RfwpnqkEU
ePMrw3KqkEjptG8R8ak4z6tDfaVkptFoIJYqymhilbVNioadUT1SJsBboVfutrs7
tBLvzn78c+3YOZGK7Iicy1pi9BM+fZcK6G/jiyj3rJNqFM7RlKsIIkdhX+Ktfzza
IDA3DB3/gOAC461P9zZUYGGl/CwSsRnQBYSyjz1QCnn7FF6LOiwsIKr4hQqQ2uQ2
ea2St9twP+kEREeDcyg9rq/43xAZflw0QowdO5/gYBulYyyoPzZswIPXOAKDx96g
gUIJMTfo2pRDD1jQK/2A1dN6TtiCw8X1+ITuIT2oB8MBYCYbmngBzdpKyADiTV/W
mJkGveKyL99qH+GZp8EDSCAVYX+IjH7gsUxVQnoHqpBbVbvUgpp44+1sAOYK9prq
1exspMhC+oPd4ICfNYv4XCQLnPAwDWpOePEFP4zBpwVkLufWvz5hcipmk1cebSmP
SHfqRtQKE5VsPNTfrt7DH+AUsB/Aj8LtGprLadVQJAR4TgYzuEoKJsdKoe3Em+b6
h1Fcpkc+w+4QtGQXciCl
=FOo8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1998-1
October 22, 2013
linux vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive information in kernel memory. (CVE-2013-2237)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)
Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)
Kees Cook discovered an information leak in the Linux kernel's Human
Interface Device (HID) subsystem when CONFIG_HID_SENSOR_HUB is enabled. A
physically proximate attacker could obtain potentially sensitive
information from kernel memory via a specially crafted device.
(CVE-2013-2898)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)
A flaw was discovered in how the Linux Kernel's networking stack checks scm
credentials when used with namespaces. A local attacker could exploit this
flaw to gain privileges. (CVE-2013-4300)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
linux-image-3.8.0-32-generic 3.8.0-32.47
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-1998-1
CVE-2013-2237, CVE-2013-2888, CVE-2013-2892, CVE-2013-2896,
CVE-2013-2898, CVE-2013-2899, CVE-2013-4300
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.8.0-32.47
[USN-1997-1] Linux kernel (OMAP4) vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSZf/mAAoJEAUvNnAY1cPY9UMQAImDd73DPKjdDrQUIdQpZTNX
5NKDLsnQrWPc+1zPg5TtjxIb/mahsidjHWjnz4npLivbJjQADq4+vt7dUmc25qCz
6NSFQAH8hktORo9dv7I5uIxEq+QQeDLdx0KDlXMBr+z45+pWQcnern2+HOOD48lo
U5DfwKHcUFtYYDkDa+iu8A5tRzLkHukf5X9WBZ3dV8WzP+Rx3dtK1P1rrL/ud7M1
tPo0I3cvV/ypKImIv0lOaLsaXsAOAZToqEFGEPQeKfcxVIJVOxPpTkbAOLGFUNq2
kuPhiJ4MtBICkVWCoAm3QcP7S3uGkvzpLYBxVO4OWHSRo2PdYFnR5GANn4LG/f4J
VJ82Vk6ArQVv3cFp3qUZUeLjCWVlBcEK3POIZugfJkGwEwcSy6uXeELJtUz+w3tj
ojYTksSwP7pOsutmNM9cAhTWlWYMWYdEnAR8EIzFbMqhC85Vyel4eZZf/o31ri61
01Dk178XrBZ9MIhe+TsEk3Vzgi+nf8BljqyKX0HF3AxPTvuyC53ox8WM7UmgBxuf
3qPsZ0AgoLFYdxzR+WprjyRwNlH7sdkr1dKjA4opE0zDCgWICoDtjKUTtu/sZFbH
dhxHFCSd1uslFHcz9/snz6bDpbHcUEJxASjH69JtcvUuyBSouLAui5kXWRr9OhyF
yviZNqpZBtrDvT/lxg5s
=MTuJ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1997-1
October 22, 2013
linux-ti-omap4 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
Summary:
The system could be made to expose sensitive information to a local user.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
linux-image-3.5.0-234-omap4 3.5.0-234.50
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-1997-1
CVE-2013-2147
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-234.50
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSZf/mAAoJEAUvNnAY1cPY9UMQAImDd73DPKjdDrQUIdQpZTNX
5NKDLsnQrWPc+1zPg5TtjxIb/mahsidjHWjnz4npLivbJjQADq4+vt7dUmc25qCz
6NSFQAH8hktORo9dv7I5uIxEq+QQeDLdx0KDlXMBr+z45+pWQcnern2+HOOD48lo
U5DfwKHcUFtYYDkDa+iu8A5tRzLkHukf5X9WBZ3dV8WzP+Rx3dtK1P1rrL/ud7M1
tPo0I3cvV/ypKImIv0lOaLsaXsAOAZToqEFGEPQeKfcxVIJVOxPpTkbAOLGFUNq2
kuPhiJ4MtBICkVWCoAm3QcP7S3uGkvzpLYBxVO4OWHSRo2PdYFnR5GANn4LG/f4J
VJ82Vk6ArQVv3cFp3qUZUeLjCWVlBcEK3POIZugfJkGwEwcSy6uXeELJtUz+w3tj
ojYTksSwP7pOsutmNM9cAhTWlWYMWYdEnAR8EIzFbMqhC85Vyel4eZZf/o31ri61
01Dk178XrBZ9MIhe+TsEk3Vzgi+nf8BljqyKX0HF3AxPTvuyC53ox8WM7UmgBxuf
3qPsZ0AgoLFYdxzR+WprjyRwNlH7sdkr1dKjA4opE0zDCgWICoDtjKUTtu/sZFbH
dhxHFCSd1uslFHcz9/snz6bDpbHcUEJxASjH69JtcvUuyBSouLAui5kXWRr9OhyF
yviZNqpZBtrDvT/lxg5s
=MTuJ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1997-1
October 22, 2013
linux-ti-omap4 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
Summary:
The system could be made to expose sensitive information to a local user.
Software Description:
- linux-ti-omap4: Linux kernel for OMAP4
Details:
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
linux-image-3.5.0-234-omap4 3.5.0-234.50
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.
References:
http://www.ubuntu.com/usn/usn-1997-1
CVE-2013-2147
Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.5.0-234.50
Subscribe to:
Posts (Atom)