USN-1829-1: Linux kernel (EC2) vulnerabilities
Mathias Krause discovered an information leak in the Linux kernel's ISO 9660 CDROM file system driver. A local user could exploit this flaw to examine some of the kernel's heap memory. (CVE-2012-6549) Mathias Krause discovered a flaw in xfrmuser in the Linux kernel. A local attacker with NETADMIN capability could potentially exploit this flaw to escalate privileges. (CVE-2013-1826) A buffer overflow was discovered in the Linux Kernel's USB subsystem for devices reporting the cdc-wdm class. A specially crafted USB device when plugged-in could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2013-1860) An information leak was discovered in the Linux kernel's /dev/dvb device. A local user could exploit this flaw to obtain sensitive information from the kernel's stack memory. (CVE-2013-1928) An information leak in the Linux kernel's dcb netlink interface was discovered. A local user could obtain sensitive information by examining kernel stack memory. (CVE-2013-2634)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-1829-1?
The severity of USN-1829-1 is classified as a medium risk due to the potential for local users to exploit the information leak.
How do I fix USN-1829-1?
To fix USN-1829-1, you should update your system to the patched version of the linux-image package, specifically 2.6.32-352.65 or higher.
What systems are affected by USN-1829-1?
USN-1829-1 affects Ubuntu 10.04 systems running the linux-image-2.6.32-352-ec2 package.
What CVEs are associated with USN-1829-1?
USN-1829-1 addresses multiple CVEs, including CVE-2012-6549, CVE-2013-1826, and CVE-2013-1860.
Who discovered the vulnerabilities in USN-1829-1?
The vulnerabilities in USN-1829-1 were discovered by researcher Mathias Krause.