USN-1236-1: Linux kernel vulnerabilities
It was discovered that the Auerswald usb driver incorrectly handled lengths of the USB string descriptors. A local attacker with physical access could insert a specially crafted USB device and gain root privileges. (CVE-2009-4067) It was discovered that the Stream Control Transmission Protocol (SCTP) implementation incorrectly calculated lengths. If the net.sctp.addipenable variable was turned on, a remote attacker could send specially crafted traffic to crash the system. (CVE-2011-1573) Vasiliy Kulikov discovered that taskstats did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2494) Vasiliy Kulikov discovered that /proc/PID/io did not enforce access restrictions. A local attacker could exploit this to read certain information, leading to a loss of privacy. (CVE-2011-2495) Dan Kaminsky discovered that the kernel incorrectly handled random sequence number generation. An attacker could use this flaw to possibly predict sequence numbers and inject packets. (CVE-2011-3188)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-1236-1?
USN-1236-1 has a high severity rating due to the potential for local attackers with physical access to exploit the vulnerability and gain root privileges.
How do I fix USN-1236-1?
To remediate USN-1236-1, upgrade to the patched linux-image packages version 2.6.24-29.95 or later on Ubuntu 8.04.
What systems are affected by USN-1236-1?
USN-1236-1 affects various linux-image packages on Ubuntu 8.04, including generic, server, and architecture-specific images.
Can a remote attacker exploit USN-1236-1?
No, USN-1236-1 requires physical access to the affected system, thereby preventing remote exploitation.
What is CVE-2009-4067 related to USN-1236-1?
CVE-2009-4067 describes the vulnerability that allows local attackers to execute arbitrary code with root privileges via crafted USB devices.