USN-1563-1: Linux kernel (Oneiric backport) vulnerability
A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS) protocol implementation. A local, unprivileged user could use this flaw to cause a denial of service. (CVE-2012-2372) Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP device driver. A local user could exploit this flaw to examine part of the kernel's stack memory. (CVE-2012-6547) A flaw was found in Linux kernel's validation of CIPSO (Common IP Security Option) options set from userspace. A local user that can set a socket's CIPSO options could exploit this flaw to cause a denial of service (crash the system). (CVE-2013-0310)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1563-1?
The severity of USN-1563-1 is classified as a denial of service vulnerability affecting local, unprivileged users.
How do I fix USN-1563-1?
To fix USN-1563-1, update to the recommended version of the affected Linux kernel packages for Ubuntu 10.04.
What systems are affected by USN-1563-1?
USN-1563-1 affects Ubuntu 10.04 systems running specific versions of Linux kernel packages.
What specific vulnerabilities are reported in USN-1563-1?
USN-1563-1 reports on CVE-2012-2372 as an information leak and denial of service vulnerability in the Linux kernel.
Who discovered the vulnerabilities in USN-1563-1?
The vulnerabilities in USN-1563-1 were discovered by Mathias Krause.