Executive Summary

Summary
Title Linux kernel (OMAP4) vulnerabilities
Informations
NameUSN-1325-1First vendor Publication2012-01-11
VendorUbuntuLast vendor Modification2012-01-11
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:H/Au:N/C:N/I:N/A:C)
Cvss Base Score5.4Attack RangeNetwork
Cvss Impact Score6.9Attack ComplexityHigh
Cvss Expoit Score4.9AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

Peter Huewe discovered an information leak in the handling of reading
security-related TPM data. A local, unprivileged user could read the
results of a previous TPM command. (CVE-2011-1162)

Clement Lecigne discovered a bug in the HFS filesystem. A local attacker
could exploit this to cause a kernel oops. (CVE-2011-2203)

Han-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user
who can mount a FUSE file system could cause a denial of service.
(CVE-2011-3353)

A flaw was found in the b43 driver in the Linux kernel. An attacker could
use this flaw to cause a denial of service if the system has an active
wireless interface using the b43 driver. (CVE-2011-3359)

A flaw was found in how the Linux kernel handles user-defined key types. An
unprivileged local user could exploit this to crash the system.
(CVE-2011-4110)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
linux-image-2.6.35-903-omap4 2.6.35-903.29

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1325-1
CVE-2011-1162, CVE-2011-2203, CVE-2011-3353, CVE-2011-3359,
CVE-2011-4110

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.29

Original Source

Url : http://www.ubuntu.com/usn/USN-1325-1

CWE : Common Weakness Enumeration

idName
CWE-264Permissions, Privileges, and Access Controls
CWE-119Failure to Constrain Operations within the Bounds of a Memory Buffer
CWE-200Information Exposure

CPE : Common Platform Enumeration

TypeDescriptionCount
Os904

Open Source Vulnerability Database (OSVDB)

idDescription
77658Linux Kernel hfs_find_init() Function NULL Pointer Dereference Local DoS
77450Linux Kernel security/keys/user_defined.c user_update() Function NULL Pointer...
77293Linux Kernel b43 Driver Wireless Interface Frame Parsing Remote DoS
77292Linux Kernel tpm_read() Local TPM Command Result Disclosure
76259Linux Kernel fs/fuse/dev.fuse_notify_inval_entry() Function FUSE_NOTIFY_INVAL...