First published: Tue Aug 20 2013(Updated: )
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client. A remote attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2013-1059) An information leak was discovered in the Linux kernel's fanotify interface. A local user could exploit this flaw to obtain sensitive information from kernel memory. (CVE-2013-2148) Jonathan Salwan discovered an information leak in the Linux kernel's cdrom driver. A local user can exploit this leak to obtain sensitive information from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164) Kees Cook discovered a format string vulnerability in the Linux kernel's disk block layer. A local user with administrator privileges could exploit this flaw to gain kernel privileges. (CVE-2013-2851)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-3.5.0-39-generic | <3.5.0-39.60 | 3.5.0-39.60 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-39-powerpc-smp | <3.5.0-39.60 | 3.5.0-39.60 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-39-highbank | <3.5.0-39.60 | 3.5.0-39.60 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-39-powerpc64-smp | <3.5.0-39.60 | 3.5.0-39.60 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-39-omap | <3.5.0-39.60 | 3.5.0-39.60 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-1932-1 is significant, as it could allow a remote attacker to cause a denial of service.
To fix USN-1932-1, you should upgrade to the linux-image package version 3.5.0-39.60 or later.
USN-1932-1 affects Ubuntu 12.10 systems running various linux-image packages.
USN-1932-1 addresses a null pointer dereference flaw and an information leak in the Linux kernel.
The vulnerabilities in USN-1932-1 were reported by Chanam Park.