USN-1917-1: Linux kernel vulnerability
Published Jul 29, 2013
·Updated
Kees Cook discovered a format string vulnerability in the Broadcom B43 wireless driver for the Linux kernel. A local user could exploit this flaw to gain administrative privileges.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/linux-image-3.5.0-37-powerpc64-smp<3.5.0-37.58
3.5.0-37.58
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-37-highbank<3.5.0-37.58
3.5.0-37.58
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-37-omap<3.5.0-37.58
3.5.0-37.58
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-37-powerpc-smp<3.5.0-37.58
3.5.0-37.58
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-37-generic<3.5.0-37.58
3.5.0-37.58
Ubuntu Ubuntu=12.10
Event History
Jul 29, 2013
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-1917-1?
The severity of USN-1917-1 is critically high due to the potential for local users to gain administrative privileges.
2
How do I fix USN-1917-1?
To fix USN-1917-1, upgrade the affected packages to version 3.5.0-37.58 or later.
3
Which Ubuntu versions are affected by USN-1917-1?
USN-1917-1 affects Ubuntu version 12.10.
4
What type of vulnerability is described in USN-1917-1?
USN-1917-1 describes a format string vulnerability in the Broadcom B43 wireless driver.
5
Can a remote attacker exploit USN-1917-1?
No, USN-1917-1 requires local access for exploitation.