USN-1133-1: Linux kernel vulnerabilities
Nelson Elhage discovered that Econet did not correctly handle AUN packets over UDP. A local attacker could send specially crafted traffic to crash the system, leading to a denial of service. (CVE-2010-4342) Dan Rosenberg discovered that the OSS subsystem did not handle name termination correctly. A local attacker could exploit this crash the system or gain root privileges. (CVE-2010-4527) Dan Rosenberg discovered that IRDA did not correctly check the size of buffers. On non-x86 systems, a local attacker could exploit this to read kernel heap memory, leading to a loss of privacy. (CVE-2010-4529) Dan Carpenter discovered that the TTPCI DVB driver did not check certain values during an ioctl. If the dvb-ttpci module was loaded, a local attacker could exploit this to crash the system, leading to a denial of service, or possibly gain root privileges. (CVE-2011-0521)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-1133-1?
The severity of USN-1133-1 is classified as important due to the potential for denial of service attacks.
How do I fix USN-1133-1?
To fix USN-1133-1, you should upgrade to the latest version of the affected packages listed in the advisory.
Who discovered the vulnerabilities in USN-1133-1?
The vulnerabilities in USN-1133-1 were discovered by Nelson Elhage and Dan Rosenberg.
What type of vulnerabilities does USN-1133-1 address?
USN-1133-1 addresses vulnerabilities related to improper handling of AUN packets over UDP and issues in the OSS subsystem.
Which Ubuntu version is affected by USN-1133-1?
USN-1133-1 affects Ubuntu version 8.04.