USN-1788-1: Linux kernel (Oneiric backport) vulnerabilities
Emese Revfy discovered that in the Linux kernel signal handlers could leak address information across an exec, making it possible to bypass ASLR (Address Space Layout Randomization). A local user could use this flaw to bypass ASLR to reliably deliver an exploit payload that would otherwise be stopped (by ASLR). (CVE-2013-0914) A memory use after free error was discovered in the Linux kernel's tmpfs filesystem. A local user could exploit this flaw to gain privileges or cause a denial of service (system crash). (CVE-2013-1767) Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user could exploit this flaw to cause a denial of service (system crash). (CVE-2013-1792)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1788-1?
USN-1788-1 has a high severity level due to its potential to bypass Address Space Layout Randomization.
How do I fix USN-1788-1?
To fix USN-1788-1, you should upgrade to linux-image-3.0.0-32.51~lucid1 or later on Ubuntu 10.04.
Who is affected by USN-1788-1?
USN-1788-1 affects local users on Ubuntu 10.04 with specific versions of the Linux kernel.
What vulnerability does USN-1788-1 address?
USN-1788-1 addresses a vulnerability in the Linux kernel that allows local users to leak address information through signal handlers.
Can USN-1788-1 be exploited remotely?
No, USN-1788-1 is a local privilege escalation vulnerability and cannot be exploited remotely.