Executive Summary
| Summary | |
|---|---|
| Title | Linux kernel vulnerabilities |
| Informations | |||
|---|---|---|---|
| Name | USN-1291-1 | First vendor Publication | 2011-12-08 |
| Vendor | Ubuntu | Last vendor Modification | 2011-12-08 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 7.2 | Attack Range | Local |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 3.9 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 8.04 LTS Summary: Several security issues were fixed in XXX-APP-XXX. Software Description: - linux: Linux kernel Details: A bug was discovered in the XFS filesystem's handling of pathnames. A local attacker could exploit this to crash the system, leading to a denial of service, or gain root privileges. (CVE-2011-4077) A flaw was found in the Journaling Block Device (JBD). A local attacker able to mount ext3 or ext4 file systems could exploit this to crash the system, leading to a denial of service. (CVE-2011-4132) Clement Lecigne discovered a bug in the HFS file system bounds checking. When a malformed HFS file system is mounted a local user could crash the system or gain root privileges. (CVE-2011-4330) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 8.04 LTS: linux-image-2.6.24-30-386 2.6.24-30.97 linux-image-2.6.24-30-generic 2.6.24-30.97 linux-image-2.6.24-30-hppa32 2.6.24-30.97 linux-image-2.6.24-30-hppa64 2.6.24-30.97 linux-image-2.6.24-30-itanium 2.6.24-30.97 linux-image-2.6.24-30-lpia 2.6.24-30.97 linux-image-2.6.24-30-lpiacompat 2.6.24-30.97 linux-image-2.6.24-30-mckinley 2.6.24-30.97 linux-image-2.6.24-30-openvz 2.6.24-30.97 linux-image-2.6.24-30-powerpc 2.6.24-30.97 linux-image-2.6.24-30-powerpc-smp 2.6.24-30.97 linux-image-2.6.24-30-powerpc64-smp 2.6.24-30.97 linux-image-2.6.24-30-rt 2.6.24-30.97 linux-image-2.6.24-30-server 2.6.24-30.97 linux-image-2.6.24-30-sparc64 2.6.24-30.97 linux-image-2.6.24-30-sparc64-smp 2.6.24-30.97 linux-image-2.6.24-30-virtual 2.6.24-30.97 linux-image-2.6.24-30-xen 2.6.24-30.97 After a standard system update you need to reboot your computer to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1291-1 CVE-2011-4077, CVE-2011-4132, CVE-2011-4330 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.24-30.97 |
Original Source
| Url : http://www.ubuntu.com/usn/USN-1291-1 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
| CWE-20 | Improper Input Validation |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Os | 2 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 77683 | Linux Kernel HFS File System Mount Local Privilege Escalation |
| 77092 | Linux Kernel fs/jbd/journal.c journal_get_superblock() ext3 Image Handling Lo... |
| 76641 | Linux Kernel fs/xfs/xfs_vnodeops.c xfs_readlink() Function XFS Image Handling... |

USN-1291-1
(High)
(Medium)
(Low)





