{"cves":[{"id":"CVE-2011-2977","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before\n4.1.3 on Windows does not delete the temporary files associated with\nuploaded attachments, which allows local users to obtain sensitive\ninformation by reading these files. NOTE: this issue exists because of a\nregression in 3.6.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2977"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=660502"],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.6,4.0.2,4.1.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2976","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through\n2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote\nattackers to inject arbitrary web script or HTML via vectors involving a\nBUGLIST cookie.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2976"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=660053"],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"3.6.3.0-2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.6.3.0-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.12","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2381","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x\nthrough 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x\nbefore 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject\narbitrary e-mail headers via an attachment description in a flagmail\nnotification.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2381"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=657158"],"patches":{"bugzilla":["vendor: http://www.debian.org/security/2011/dsa-2322"]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.12,3.6.6,4.0.2,4.1.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2380","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12,\n3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before\n4.1.3 allows remote attackers to determine the existence of private group\nnames via a crafted parameter during (1) bug creation or (2) bug editing.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2380"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=653477"],"patches":{"bugzilla":["vendor: http://www.debian.org/security/2011/dsa-2322"]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.12,3.6.6,4.0.2,4.1.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2379","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7,\n3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x,\n4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9\nor Safari before 5.0.6 is used for Raw Unified mode, allows remote\nattackers to inject arbitrary web script or HTML via a crafted patch,\nrelated to content sniffing.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.bugzilla.org/security/3.4.11/","https://www.cve.org/CVERecord?id=CVE-2011-2379"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=637981"],"patches":{"bugzilla":["vendor: http://www.debian.org/security/2011/dsa-2322"]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"dropped by debian","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.12,3.6.6,4.0.2,4.1.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7294","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 4.0.211.0 cannot properly restrict modifications to\ncookies established in HTTPS sessions, which allows man-in-the-middle\nattackers to overwrite or delete arbitrary cookies via a Set-Cookie header\nin an HTTP response, related to lack of the HTTP Strict Transport Security\n(HSTS) includeSubDomains feature, aka a \"cookie forcing\" issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://scarybeastsecurity.blogspot.com/2011/02/some-less-obvious-benefits-of-hsts.html","http://scarybeastsecurity.blogspot.com/2008/11/cookie-forcing.html","http://michael-coates.blogspot.com/2010/01/cookie-forcing-trust-your-cookies-no.html","https://www.cve.org/CVERecord?id=CVE-2008-7294"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=660053"],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"14.0.835.202~r103287-0ubuntu0.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"14.0.835.202~r103287-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"14.0.835.202~r103287-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7293","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMozilla Firefox before 4 cannot properly restrict modifications to cookies\nestablished in HTTPS sessions, which allows man-in-the-middle attackers to\noverwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP\nresponse, related to lack of the HTTP Strict Transport Security (HSTS)\nincludeSubDomains feature, aka a \"cookie forcing\" issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://scarybeastsecurity.blogspot.com/2011/02/some-less-obvious-benefits-of-hsts.html","http://scarybeastsecurity.blogspot.com/2008/11/cookie-forcing.html","http://michael-coates.blogspot.com/2010/01/cookie-forcing-trust-your-cookies-no.html","https://www.cve.org/CVERecord?id=CVE-2008-7293"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=660053"],"patches":{"firefox":[],"firefox-3.0":[],"firefox-3.5":[],"xulrunner-1.9.2":[],"xulrunner-2.0":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.23+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.23+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"7.0.1+build1+nobinonly-0ubuntu0.11.04.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"hardy","status":"released","description":"3.6.17+build3+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"firefox-3.5","source":"https://ubuntu.com/security/cve?package=firefox-3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.5","debian":"https://tracker.debian.org/pkg/firefox-3.5","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xulrunner-2.0","source":"https://ubuntu.com/security/cve?package=xulrunner-2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-2.0","debian":"https://tracker.debian.org/pkg/xulrunner-2.0","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2008-7292","published":"2011-08-09T19:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3\non Windows does not delete the temporary files associated with uploaded\nattachments, which allows local users to obtain sensitive information by\nreading these files, a different vulnerability than CVE-2011-2977.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"looks windows-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2008-7292"],"bugs":["https://bugzilla.mozilla.org/show_bug.cgi?id=660502","https://bugzilla.mozilla.org/show_bug.cgi?id=414002"],"patches":{"bugzilla":[]},"tags":{},"packages":[{"name":"bugzilla","source":"https://ubuntu.com/security/cve?package=bugzilla","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bugzilla","debian":"https://tracker.debian.org/pkg/bugzilla","statuses":[{"release_codename":"hardy","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"windows-only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.3,3.0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1837","published":"2011-08-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe lock-counter implementation in utils/mount.ecryptfs_private.c in\necryptfs-utils before 90 allows local users to overwrite arbitrary files\nvia unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://www.cve.org/CVERecord?id=CVE-2011-1837"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/732628"],"patches":{"ecryptfs-utils":[]},"tags":{"ecryptfs-utils_maverick":["symlink-restriction"],"ecryptfs-utils_natty":["symlink-restriction"],"ecryptfs-utils_oneiric":["symlink-restriction"]},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"83-0ubuntu3.2.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"83-0ubuntu3.2.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"89-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1188-1"],"notices":[{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]}]},{"id":"CVE-2011-1836","published":"2011-08-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nutils/ecryptfs-recover-private in ecryptfs-utils before 90 does not\nestablish a subdirectory with safe permissions, which might allow local\nusers to bypass intended access restrictions via standard filesystem\noperations during the recovery process.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://www.cve.org/CVERecord?id=CVE-2011-1836"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/732628"],"patches":{"ecryptfs-utils":[]},"tags":{},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1188-1"],"notices":[{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]}]},{"id":"CVE-2011-1835","published":"2011-08-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe encrypted private-directory setup process in\nutils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly\nensure that the passphrase file is created, which might allow local users\nto bypass intended access restrictions at a certain time in the new-user\ncreation steps.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://www.cve.org/CVERecord?id=CVE-2011-1835"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/732628"],"patches":{"ecryptfs-utils":[]},"tags":{},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"83-0ubuntu3.2.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"83-0ubuntu3.2.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1188-1"],"notices":[{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]}]},{"id":"CVE-2011-1834","published":"2011-08-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nutils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not\nproperly maintain the mtab file during error conditions, which allows local\nusers to cause a denial of service (table corruption) or bypass intended\nunmounting restrictions via a umount system call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://www.cve.org/CVERecord?id=CVE-2011-1834"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/732628"],"patches":{"ecryptfs-utils":[]},"tags":{},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"83-0ubuntu3.2.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"83-0ubuntu3.2.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1188-1"],"notices":[{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]}]},{"id":"CVE-2011-1833","published":"2011-08-09T00:00:00","updated_at":"2026-07-04T07:34:14.454335+00:00","description":"\nRace condition in the ecryptfs_mount function in fs/ecryptfs/main.c in the\neCryptfs subsystem in the Linux kernel before 3.1 allows local users to\nbypass intended file permissions via a mount.ecryptfs_private mount with a\nmismatched uid.","ubuntu_description":"\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service.","notes":[{"author":"mdeslaur","note":"There are two parts to this fix, 1- kernel fix, 2- userspace fix"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://ubuntu.com/security/notices/USN-1202-1","https://ubuntu.com/security/notices/USN-1204-1","https://ubuntu.com/security/notices/USN-1212-1","https://ubuntu.com/security/notices/USN-1211-1","https://ubuntu.com/security/notices/USN-1219-1","https://ubuntu.com/security/notices/USN-1227-1","https://ubuntu.com/security/notices/USN-1239-1","https://ubuntu.com/security/notices/USN-1245-1","https://ubuntu.com/security/notices/USN-1240-1","https://ubuntu.com/security/notices/USN-1253-1","https://ubuntu.com/security/notices/USN-1256-1","https://www.cve.org/CVERecord?id=CVE-2011-1833"],"bugs":["https://launchpad.net/bugs/732628"],"patches":{"ecryptfs-utils":[],"linux":["break-fix: 237fead619984cc48818fe12ee0ceada3f55b012 764355487ea220fdc2faf128d577d7f679b91f97"],"linux-ec2":[],"linux-mvl-dove":[],"linux-ti-omap4":[],"linux-lts-backport-maverick":[],"linux-fsl-imx51":[],"linux-lts-backport-natty":[],"linux-lts-backport-oneiric":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"83-0ubuntu3.2.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"83-0ubuntu3.2.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"89-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-35.78","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-30.60","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-11.49","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.0.0-8.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-319.39","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-610.27","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-30.60~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-natty","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-natty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-natty","debian":"https://tracker.debian.org/pkg/linux-lts-backport-natty","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.38-11.49~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-oneiric","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-oneiric","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-oneiric","debian":"https://tracker.debian.org/pkg/linux-lts-backport-oneiric","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-219.37","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-419.37","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.23","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.6.38-1209.15","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"3.0.0-1201.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1~rc2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1219-1","USN-1253-1","USN-1211-1","USN-1202-1","USN-1239-1","USN-1188-1","USN-1227-1","USN-1240-1","USN-1204-1","USN-1256-1","USN-1245-1","USN-1212-1"],"notices":[{"id":"USN-1219-1","title":"Linux kernel (Maverick backport) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-29T17:17:31.203370","description":"\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nDan Rosenberg discovered that the IPv4 diagnostic routines did not\ncorrectly validate certain requests. A local attacker could exploit this to\nconsume CPU resources, leading to a denial of service. (CVE-2011-2213)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nMauro Carvalho Chehab discovered that the si4713 radio driver did not\ncorrectly check the length of memory copies. If this hardware was\navailable, a local attacker could exploit this to crash the system or gain\nroot privileges. (CVE-2011-2700)\n\nHerbert Xu discovered that certain fields were incorrectly handled when\nGeneric Receive Offload (CVE-2011-2723)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nGideon Naim discovered a flaw in the Linux kernel's handling VLAN 0 frames.\nAn attacker on the local network could exploit this flaw to cause a denial\nof service. (CVE-2011-3593)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-30.60~lucid1","description":"Linux kernel backport from Maverick","is_source":true},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.60~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.60~lucid1"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.60~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.60~lucid1"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.60~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.60~lucid1"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.60~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-30.60~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-1576","CVE-2011-1776","CVE-2011-1833","CVE-2011-2213","CVE-2011-2497","CVE-2011-2699","CVE-2011-2700","CVE-2011-2723","CVE-2011-2918","CVE-2011-2928","CVE-2011-3191","CVE-2011-3593"]},{"id":"USN-1253-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-11-08T19:40:09.550160","description":"\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2494)\n\nVasiliy Kulikov discovered that /proc/PID/io did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2495)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nIt was discovered that the EXT4 filesystem contained multiple off-by-one\nflaws. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2011-2695)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nChristian Ohm discovered that the perf command looks for configuration\nfiles in the current directory. If a privileged user were tricked into\nrunning perf in a directory containing a malicious configuration file, an\nattacker could run arbitrary commands and possibly gain privileges.\n(CVE-2011-2905)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nDan Kaminsky discovered that the kernel incorrectly handled random sequence\nnumber generation. An attacker could use this flaw to possibly predict\nsequence numbers and inject packets. (CVE-2011-3188)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nGideon Naim discovered a flaw in the Linux kernel's handling VLAN 0 frames.\nAn attacker on the local network could exploit this flaw to cause a denial\nof service. (CVE-2011-3593)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux","version":"2.6.32-35.78","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-35-generic","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-sparc64-smp","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-preempt","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-powerpc-smp","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-versatile","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-powerpc64-smp","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-virtual","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-generic-pae","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-lpia","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-powerpc","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-sparc64","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-server","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-ia64","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"},{"name":"linux-image-2.6.32-35-386","version":"2.6.32-35.78","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-35.78"}]},"type":"USN","cves_ids":["CVE-2011-1576","CVE-2011-1833","CVE-2011-2494","CVE-2011-2495","CVE-2011-2497","CVE-2011-2695","CVE-2011-2699","CVE-2011-2905","CVE-2011-2928","CVE-2011-3188","CVE-2011-3191","CVE-2011-3353","CVE-2011-3593"]},{"id":"USN-1211-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws have been fixed. \n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-21T12:23:31.822184","description":"\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nIt was discovered that GFS2 did not correctly check block sizes. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2011-2689)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux","version":"2.6.38-11.50","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.38-11-generic","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-omap","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-powerpc-smp","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-versatile","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-powerpc64-smp","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-virtual","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-generic-pae","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-powerpc","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"},{"name":"linux-image-2.6.38-11-server","version":"2.6.38-11.50","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.38-11.50"}]},"type":"USN","cves_ids":["CVE-2011-1020","CVE-2011-1493","CVE-2011-1833","CVE-2011-2492","CVE-2011-2689","CVE-2011-2699","CVE-2011-2918","CVE-2011-3637","CVE-2011-4914"]},{"id":"USN-1202-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-13T20:04:34.377322","description":"\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nDan Rosenburg discovered that the CAN subsystem leaked kernel addresses\ninto the /proc filesystem. A local attacker could use this to increase the\nchances of a successful memory corruption exploit. (CVE-2010-4565)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nJens Kuehnel discovered that the InfiniBand driver contained a race\ncondition. On systems using InfiniBand, a local attacker could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2011-0695)\n\nDan Rosenberg discovered that XFS did not correctly initialize memory. A\nlocal attacker could make crafted ioctl calls to leak portions of kernel\nstack memory, leading to a loss of privacy. (CVE-2011-0711)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nMarek Olšák discovered that the Radeon GPU drivers did not correctly\nvalidate certain registers. On systems with specific hardware, a local\nattacker could exploit this to write to arbitrary video memory.\n(CVE-2011-1016)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nVasiliy Kulikov discovered that the CAP_SYS_MODULE capability was not\nneeded to load kernel modules. A local attacker with the CAP_NET_ADMIN\ncapability could load existing kernel modules, possibly increasing the\nattack surface available on the system. (CVE-2011-1019)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nDan Rosenberg discovered that some ALSA drivers did not correctly check the\nadapter index during ioctl calls. If this driver was loaded, a local\nattacker could make a specially crafted ioctl call to gain root privileges.\n(CVE-2011-1169)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.24","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.24","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.24"}]},"type":"USN","cves_ids":["CVE-2011-1171","CVE-2010-3297","CVE-2011-0521","CVE-2011-1163","CVE-2010-3858","CVE-2010-4163","CVE-2010-3880","CVE-2010-4073","CVE-2010-4082","CVE-2010-4162","CVE-2010-3859","CVE-2010-4075","CVE-2011-1019","CVE-2011-1170","CVE-2010-4649","CVE-2011-1090","CVE-2010-3874","CVE-2011-1082","CVE-2010-4243","CVE-2011-1012","CVE-2010-4083","CVE-2010-4655","CVE-2011-1180","CVE-2011-0695","CVE-2011-1044","CVE-2011-1173","CVE-2010-3296","CVE-2010-4169","CVE-2010-4256","CVE-2011-1172","CVE-2010-4081","CVE-2010-4242","CVE-2011-0726","CVE-2011-1080","CVE-2011-1017","CVE-2011-0463","CVE-2010-4080","CVE-2011-1079","CVE-2011-1010","CVE-2011-1013","CVE-2010-4157","CVE-2010-4565","CVE-2011-1078","CVE-2010-4077","CVE-2010-4248","CVE-2011-1169","CVE-2010-4175","CVE-2011-1020","CVE-2010-4076","CVE-2011-0712","CVE-2011-1016","CVE-2011-1160","CVE-2010-4160","CVE-2011-1093","CVE-2011-0711","CVE-2011-1577","CVE-2011-1748","CVE-2011-2492","CVE-2011-1494","CVE-2011-1478","CVE-2011-3637","CVE-2011-2918","CVE-2011-1493","CVE-2011-2022","CVE-2010-4668","CVE-2010-4656","CVE-2011-2699","CVE-2011-1746","CVE-2011-4914","CVE-2011-4913","CVE-2011-2534","CVE-2011-1745","CVE-2011-1770","CVE-2011-1833","CVE-2011-1495","CVE-2011-1598","CVE-2011-2484","CVE-2011-1593","CVE-2011-1182"]},{"id":"USN-1239-1","title":"Linux kernel (EC2) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-10-25T12:50:58.080043","description":"\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2494)\n\nVasiliy Kulikov discovered that /proc/PID/io did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2495)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nIt was discovered that the EXT4 filesystem contained multiple off-by-one\nflaws. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2011-2695)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nChristian Ohm discovered that the perf command looks for configuration\nfiles in the current directory. If a privileged user were tricked into\nrunning perf in a directory containing a malicious configuration file, an\nattacker could run arbitrary commands and possibly gain privileges.\n(CVE-2011-2905)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nDan Kaminsky discovered that the kernel incorrectly handled random sequence\nnumber generation. An attacker could use this flaw to possibly predict\nsequence numbers and inject packets. (CVE-2011-3188)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nGideon Naim discovered a flaw in the Linux kernel's handling VLAN 0 frames.\nAn attacker on the local network could exploit this flaw to cause a denial\nof service. (CVE-2011-3593)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-319.39","description":"Linux kernel for EC2","is_source":true},{"name":"linux-image-2.6.32-319-ec2","version":"2.6.32-319.39","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-319.39"}]},"type":"USN","cves_ids":["CVE-2011-1576","CVE-2011-1833","CVE-2011-2494","CVE-2011-2495","CVE-2011-2497","CVE-2011-2695","CVE-2011-2699","CVE-2011-2905","CVE-2011-2928","CVE-2011-3188","CVE-2011-3191","CVE-2011-3353","CVE-2011-3593"]},{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]},{"id":"USN-1227-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-10-11T12:32:55.245397","description":"\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nDan Rosenberg discovered that the IPv4 diagnostic routines did not\ncorrectly validate certain requests. A local attacker could exploit this to\nconsume CPU resources, leading to a denial of service. (CVE-2011-2213)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nMauro Carvalho Chehab discovered that the si4713 radio driver did not\ncorrectly check the length of memory copies. If this hardware was\navailable, a local attacker could exploit this to crash the system or gain\nroot privileges. (CVE-2011-2700)\n\nHerbert Xu discovered that certain fields were incorrectly handled when\nGeneric Receive Offload (CVE-2011-2723)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nGideon Naim discovered a flaw in the Linux kernel's handling VLAN 0 frames.\nAn attacker on the local network could exploit this flaw to cause a denial\nof service. (CVE-2011-3593)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux","version":"2.6.35-30.60","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-30-powerpc-smp","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-versatile","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-server","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-powerpc64-smp","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-virtual","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-generic-pae","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-omap","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-generic","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"},{"name":"linux-image-2.6.35-30-powerpc","version":"2.6.35-30.60","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-30.60"}]},"type":"USN","cves_ids":["CVE-2011-1576","CVE-2011-1776","CVE-2011-1833","CVE-2011-2213","CVE-2011-2497","CVE-2011-2699","CVE-2011-2700","CVE-2011-2723","CVE-2011-2918","CVE-2011-2928","CVE-2011-3191","CVE-2011-3593"]},{"id":"USN-1240-1","title":"Linux kernel (Marvell DOVE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-10-25T12:54:00.730888","description":"\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2494)\n\nVasiliy Kulikov discovered that /proc/PID/io did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2495)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nIt was discovered that the EXT4 filesystem contained multiple off-by-one\nflaws. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2011-2695)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nChristian Ohm discovered that the perf command looks for configuration\nfiles in the current directory. If a privileged user were tricked into\nrunning perf in a directory containing a malicious configuration file, an\nattacker could run arbitrary commands and possibly gain privileges.\n(CVE-2011-2905)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nDan Kaminsky discovered that the kernel incorrectly handled random sequence\nnumber generation. An attacker could use this flaw to possibly predict\nsequence numbers and inject packets. (CVE-2011-3188)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nGideon Naim discovered a flaw in the Linux kernel's handling VLAN 0 frames.\nAn attacker on the local network could exploit this flaw to cause a denial\nof service. (CVE-2011-3593)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-219.37","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-219-dove","version":"2.6.32-219.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-219.37"}]},"type":"USN","cves_ids":["CVE-2011-1576","CVE-2011-1833","CVE-2011-2494","CVE-2011-2495","CVE-2011-2497","CVE-2011-2695","CVE-2011-2699","CVE-2011-2905","CVE-2011-2928","CVE-2011-3188","CVE-2011-3191","CVE-2011-3353","CVE-2011-3593"]},{"id":"USN-1204-1","title":"Linux kernel (i.MX51) vulnerabilities","summary":"Multiple kernel flaws have been fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-09-13T20:11:32.087550","description":"\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075, CVE-2010-4076, CVE-2010-4077)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nAlex Shi and Eric Dumazet discovered that the network stack did not\ncorrectly handle packet backlogs. A remote attacker could exploit this by\nsending a large amount of network traffic to cause the system to run out of\nmemory, leading to a denial of service. (CVE-2010-4251, CVE-2010-4805)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nKees Cook reported that /proc/pid/stat did not correctly filter certain\nmemory locations. A local attacker could determine the memory layout of\nprocesses in an attempt to increase the chances of a successful memory\ncorruption exploit. (CVE-2011-0726)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nMatthiew Herrb discovered that the drm modeset interface did not correctly\nhandle a signed comparison. A local attacker could exploit this to crash\nthe system or possibly gain root privileges. (CVE-2011-1013)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nNeil Horman discovered that NFSv4 did not correctly handle certain orders\nof operation with ACL data. A remote attacker with access to an NFSv4 mount\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2011-1090)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nTimo Warns discovered that OSF partition parsing routines did not correctly\nclear memory. A local attacker with physical access could plug in a\nspecially crafted block device to read kernel memory, leading to a loss of\nprivacy. (CVE-2011-1163)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-610.28","description":"Linux kernel for IMX51","is_source":true},{"name":"linux-image-2.6.31-610-imx51","version":"2.6.31-610.28","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-610.28"}]},"type":"USN","cves_ids":["CVE-2011-2918","CVE-2011-3637","CVE-2011-4913","CVE-2011-4914","CVE-2010-3859","CVE-2010-4075","CVE-2010-4076","CVE-2010-4077","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4251","CVE-2010-4526","CVE-2010-4649","CVE-2010-4668","CVE-2010-4805","CVE-2011-0726","CVE-2011-1010","CVE-2011-1012","CVE-2011-1013","CVE-2011-1020","CVE-2011-1044","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1082","CVE-2011-1090","CVE-2011-1093","CVE-2011-1160","CVE-2011-1163","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1478","CVE-2011-1493","CVE-2011-1577","CVE-2011-1598","CVE-2011-1770","CVE-2011-1833","CVE-2011-2484","CVE-2011-2492","CVE-2011-2534","CVE-2011-2699"]},{"id":"USN-1256-1","title":"Linux kernel (Natty backport) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-11-09T18:32:57.500558","description":"\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nRyan Sweat discovered that the GRO code did not correctly validate memory.\nIn some configurations on systems using VLANs, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1478)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nIt was discovered that the Stream Control Transmission Protocol (SCTP)\nimplementation incorrectly calculated lengths. If the net.sctp.addip_enable\nvariable was turned on, a remote attacker could send specially crafted\ntraffic to crash the system. (CVE-2011-1573)\n\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nPhil Oester discovered that the network bonding system did not correctly\nhandle large queues. On some systems, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1581)\n\nIt was discovered that CIFS incorrectly handled authentication. When a user\nhad a CIFS share mounted that required authentication, a local user could\nmount the same share without knowing the correct password. (CVE-2011-1585)\n\nIt was discovered that the GRE protocol incorrectly handled netns\ninitialization. A remote attacker could send a packet while the ip_gre\nmodule was loading, and crash the system, leading to a denial of service.\n(CVE-2011-1767)\n\nIt was discovered that the IP/IP protocol incorrectly handled netns\ninitialization. A remote attacker could send a packet while the ipip module\nwas loading, and crash the system, leading to a denial of service.\n(CVE-2011-1768)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nTimo Warns discovered that the EFI GUID partition table was not correctly\nparsed. A physically local attacker that could insert mountable devices\ncould exploit this to crash the system or possibly gain root privileges.\n(CVE-2011-1776)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nBen Hutchings reported a flaw in the kernel's handling of corrupt LDM\npartitions. A local user could exploit this to cause a denial of service or\nescalate privileges. (CVE-2011-2182)\n\nDan Rosenberg discovered that the IPv4 diagnostic routines did not\ncorrectly validate certain requests. A local attacker could exploit this to\nconsume CPU resources, leading to a denial of service. (CVE-2011-2213)\n\nIt was discovered that an mmap() call with the MAP_PRIVATE flag on\n\"/dev/zero\" was incorrectly handled. A local attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-2479)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nSami Liedes discovered that ext4 did not correctly handle missing root\ninodes. A local attacker could trigger the mount of a specially crafted\nfilesystem to cause the system to crash, leading to a denial of service.\n(CVE-2011-2493)\n\nRobert Swiecki discovered that mapping extensions were incorrectly handled.\nA local attacker could exploit this to crash the system, leading to a\ndenial of service. (CVE-2011-2496)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nBen Pfaff discovered that Classless Queuing Disciplines (qdiscs) were being\nincorrectly handled. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2011-2525)\n\nIt was discovered that GFS2 did not correctly check block sizes. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2011-2689)\n\nIt was discovered that the EXT4 filesystem contained multiple off-by-one\nflaws. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2011-2695)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nMauro Carvalho Chehab discovered that the si4713 radio driver did not\ncorrectly check the length of memory copies. If this hardware was\navailable, a local attacker could exploit this to crash the system or gain\nroot privileges. (CVE-2011-2700)\n\nHerbert Xu discovered that certain fields were incorrectly handled when\nGeneric Receive Offload (CVE-2011-2723)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nQianfeng Zhang discovered that the bridge networking interface incorrectly\nhandled certain network packets. A remote attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-2942)\n\nDan Kaminsky discovered that the kernel incorrectly handled random sequence\nnumber generation. An attacker could use this flaw to possibly predict\nsequence numbers and inject packets. (CVE-2011-3188)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nYasuaki Ishimatsu discovered a flaw in the kernel's clock implementation. A\nlocal unprivileged attacker could exploit this causing a denial of service.\n(CVE-2011-3209)\n\nYogesh Sharma discovered that CIFS did not correctly handle UNCs that had\nno prefixpaths. A local attacker with access to a CIFS partition could\nexploit this to crash the system, leading to a denial of service.\n(CVE-2011-3363)\n\nA flaw was discovered in the Linux kernel's AppArmor security interface\nwhen invalid information was written to it. An unprivileged local user\ncould use this to cause a denial of service on the system. (CVE-2011-3619)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nScot Doyle discovered that the bridge networking interface incorrectly\nhandled certain network packets. A remote attacker could exploit this to\ncrash the system, leading to a denial of service. (CVE-2011-4087)\n\nA bug was found in the way headroom check was performed in\nudp6_ufo_fragment() function. A remote attacker could use this flaw to\ncrash the system. (CVE-2011-4326)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-natty","version":"2.6.38-12.51~lucid1","description":"Linux kernel backport from Natty","is_source":true},{"name":"linux-image-2.6.38-12-generic-pae","version":"2.6.38-12.51~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-12.51~lucid1"},{"name":"linux-image-2.6.38-12-virtual","version":"2.6.38-12.51~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-12.51~lucid1"},{"name":"linux-image-2.6.38-12-server","version":"2.6.38-12.51~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-12.51~lucid1"},{"name":"linux-image-2.6.38-12-generic","version":"2.6.38-12.51~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-natty/2.6.38-12.51~lucid1"}]},"type":"USN","cves_ids":["CVE-2011-1020","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1093","CVE-2011-1160","CVE-2011-1180","CVE-2011-1478","CVE-2011-1479","CVE-2011-1493","CVE-2011-1573","CVE-2011-1576","CVE-2011-1577","CVE-2011-1581","CVE-2011-1585","CVE-2011-1767","CVE-2011-1768","CVE-2011-1771","CVE-2011-1776","CVE-2011-1833","CVE-2011-2182","CVE-2011-2213","CVE-2011-2479","CVE-2011-2484","CVE-2011-2492","CVE-2011-2493","CVE-2011-2496","CVE-2011-2497","CVE-2011-2525","CVE-2011-2689","CVE-2011-2695","CVE-2011-2699","CVE-2011-2700","CVE-2011-2723","CVE-2011-2918","CVE-2011-2928","CVE-2011-2942","CVE-2011-3188","CVE-2011-3191","CVE-2011-3209","CVE-2011-3363","CVE-2011-3619","CVE-2011-3637","CVE-2011-4087","CVE-2011-4326","CVE-2011-4914"]},{"id":"USN-1245-1","title":"Linux kernel (Marvell DOVE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-10-25T13:08:05.406130","description":"\nRyan Sweat discovered that the kernel incorrectly handled certain VLAN\npackets. On some systems, a remote attacker could send specially crafted\ntraffic to crash the system, leading to a denial of service.\n(CVE-2011-1576)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2494)\n\nVasiliy Kulikov discovered that /proc/PID/io did not enforce access\nrestrictions. A local attacker could exploit this to read certain\ninformation, leading to a loss of privacy. (CVE-2011-2495)\n\nDan Rosenberg discovered that the Bluetooth stack incorrectly handled\ncertain L2CAP requests. If a system was using Bluetooth, a remote attacker\ncould send specially crafted traffic to crash the system or gain root\nprivileges. (CVE-2011-2497)\n\nIt was discovered that the EXT4 filesystem contained multiple off-by-one\nflaws. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2011-2695)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nChristian Ohm discovered that the perf command looks for configuration\nfiles in the current directory. If a privileged user were tricked into\nrunning perf in a directory containing a malicious configuration file, an\nattacker could run arbitrary commands and possibly gain privileges.\n(CVE-2011-2905)\n\nTime Warns discovered that long symlinks were incorrectly handled on Be\nfilesystems. A local attacker could exploit this with a malformed Be\nfilesystem and crash the system, leading to a denial of service.\n(CVE-2011-2928)\n\nDan Kaminsky discovered that the kernel incorrectly handled random sequence\nnumber generation. An attacker could use this flaw to possibly predict\nsequence numbers and inject packets. (CVE-2011-3188)\n\nDarren Lavender discovered that the CIFS client incorrectly handled certain\nlarge values. A remote attacker with a malicious server could exploit this\nto crash the system or possibly execute arbitrary code as the root user.\n(CVE-2011-3191)\n\nHan-Wen Nienhuys reported a flaw in the FUSE kernel module. A local user\nwho can mount a FUSE file system could cause a denial of service.\n(CVE-2011-3353)\n\nGideon Naim discovered a flaw in the Linux kernel's handling VLAN 0 frames.\nAn attacker on the local network could exploit this flaw to cause a denial\nof service. (CVE-2011-3593)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-419.37","description":"Linux kernel for DOVE","is_source":true},{"name":"linux-image-2.6.32-419-dove","version":"2.6.32-419.37","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-419.37"}]},"type":"USN","cves_ids":["CVE-2011-1576","CVE-2011-1833","CVE-2011-2494","CVE-2011-2495","CVE-2011-2497","CVE-2011-2695","CVE-2011-2699","CVE-2011-2905","CVE-2011-2928","CVE-2011-3188","CVE-2011-3191","CVE-2011-3353","CVE-2011-3593"]},{"id":"USN-1212-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple kernel flaws have been fixed. \n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-09-21T12:31:09.943733","description":"\nGoldwyn Rodrigues discovered that the OCFS2 filesystem did not correctly\nclear memory when writing certain file holes. A local attacker could\nexploit this to read uninitialized data from the disk, leading to a loss of\nprivacy. (CVE-2011-0463)\n\nTimo Warns discovered that the LDM disk partition handling code did not\ncorrectly handle certain values. By inserting a specially crafted disk\ndevice, a local attacker could exploit this to gain root privileges.\n(CVE-2011-1017)\n\nIt was discovered that the /proc filesystem did not correctly handle\npermission changes when programs executed. A local attacker could hold open\nfiles to examine details about programs running with higher privileges,\npotentially increasing the chances of exploiting additional\nvulnerabilities. (CVE-2011-1020)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly clear\nmemory. A local attacker could exploit this to read kernel stack memory,\nleading to a loss of privacy. (CVE-2011-1078)\n\nVasiliy Kulikov discovered that the Bluetooth stack did not correctly check\nthat device name strings were NULL terminated. A local attacker could\nexploit this to crash the system, leading to a denial of service, or leak\ncontents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1079)\n\nVasiliy Kulikov discovered that bridge network filtering did not check that\nname fields were NULL terminated. A local attacker could exploit this to\nleak contents of kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1080)\n\nPeter Huewe discovered that the TPM device did not correctly initialize\nmemory. A local attacker could exploit this to read kernel heap memory\ncontents, leading to a loss of privacy. (CVE-2011-1160)\n\nVasiliy Kulikov discovered that the netfilter code did not check certain\nstrings copied from userspace. A local attacker with netfilter access could\nexploit this to read kernel memory or crash the system, leading to a denial\nof service. (CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-2534)\n\nVasiliy Kulikov discovered that the Acorn Universal Networking driver did\nnot correctly initialize memory. A remote attacker could send specially\ncrafted traffic to read kernel stack memory, leading to a loss of privacy.\n(CVE-2011-1173)\n\nDan Rosenberg discovered that the IRDA subsystem did not correctly check\ncertain field sizes. If a system was using IRDA, a remote attacker could\nsend specially crafted traffic to crash the system or gain root privileges.\n(CVE-2011-1180)\n\nJulien Tinnes discovered that the kernel did not correctly validate the\nsignal structure from tkill(). A local attacker could exploit this to send\nsignals to arbitrary threads, possibly bypassing expected restrictions.\n(CVE-2011-1182)\n\nDan Rosenberg reported errors in the OSS (Open Sound System) MIDI\ninterface. A local attacker on non-x86 systems might be able to cause a\ndenial of service. (CVE-2011-1476)\n\nDan Rosenberg reported errors in the kernel's OSS (Open Sound System)\ndriver for Yamaha FM synthesizer chips. A local user can exploit this to\ncause memory corruption, causing a denial of service or privilege\nescalation. (CVE-2011-1477)\n\nIt was discovered that the security fix for CVE-2010-4250 introduced a\nregression. A remote attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1479)\n\nDan Rosenberg discovered that the X.25 Rose network stack did not correctly\nhandle certain fields. If a system was running with Rose enabled, a remote\nattacker could send specially crafted traffic to gain root privileges.\n(CVE-2011-1493)\n\nDan Rosenberg discovered that MPT devices did not correctly validate\ncertain values in ioctl calls. If these drivers were loaded, a local\nattacker could exploit this to read arbitrary kernel memory, leading to a\nloss of privacy. (CVE-2011-1494, CVE-2011-1495)\n\nTimo Warns discovered that the GUID partition parsing routines did not\ncorrectly validate certain structures. A local attacker with physical\naccess could plug in a specially crafted block device to crash the system,\nleading to a denial of service. (CVE-2011-1577)\n\nPhil Oester discovered that the network bonding system did not correctly\nhandle large queues. On some systems, a remote attacker could send\nspecially crafted traffic to crash the system, leading to a denial of\nservice. (CVE-2011-1581)\n\nTavis Ormandy discovered that the pidmap function did not correctly handle\nlarge requests. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2011-1593)\n\nOliver Hartkopp and Dave Jones discovered that the CAN network driver did\nnot correctly validate certain socket structures. If this driver was\nloaded, a local attacker could crash the system, leading to a denial of\nservice. (CVE-2011-1598, CVE-2011-1748)\n\nVasiliy Kulikov discovered that the AGP driver did not check certain ioctl\nvalues. A local attacker with access to the video subsystem could exploit\nthis to crash the system, leading to a denial of service, or possibly gain\nroot privileges. (CVE-2011-1745, CVE-2011-2022)\n\nVasiliy Kulikov discovered that the AGP driver did not check the size of\ncertain memory allocations. A local attacker with access to the video\nsubsystem could exploit this to run the system out of memory, leading to a\ndenial of service. (CVE-2011-1746)\n\nDan Rosenberg discovered that the DCCP stack did not correctly handle\ncertain packet structures. A remote attacker could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1770)\n\nBen Greear discovered that CIFS did not correctly handle direct I/O. A\nlocal attacker with access to a CIFS partition could exploit this to crash\nthe system, leading to a denial of service. (CVE-2011-1771)\n\nVasiliy Kulikov and Dan Rosenberg discovered that ecryptfs did not\ncorrectly check the origin of mount points. A local attacker could exploit\nthis to trick the system into unmounting arbitrary mount points, leading to\na denial of service. (CVE-2011-1833)\n\nVasiliy Kulikov discovered that taskstats listeners were not correctly\nhandled. A local attacker could expoit this to exhaust memory and CPU\nresources, leading to a denial of service. (CVE-2011-2484)\n\nIt was discovered that Bluetooth l2cap and rfcomm did not correctly\ninitialize structures. A local attacker could exploit this to read portions\nof the kernel stack, leading to a loss of privacy. (CVE-2011-2492)\n\nSami Liedes discovered that ext4 did not correctly handle missing root\ninodes. A local attacker could trigger the mount of a specially crafted\nfilesystem to cause the system to crash, leading to a denial of service.\n(CVE-2011-2493)\n\nIt was discovered that GFS2 did not correctly check block sizes. A local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2011-2689)\n\nFernando Gont discovered that the IPv6 stack used predictable fragment\nidentification numbers. A remote attacker could exploit this to exhaust\nnetwork resources, leading to a denial of service. (CVE-2011-2699)\n\nThe performance counter subsystem did not correctly handle certain\ncounters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2011-2918)\n\nA flaw was found in the b43 driver in the Linux kernel. An attacker could\nuse this flaw to cause a denial of service if the system has an active\nwireless interface using the b43 driver. (CVE-2011-3359)\n\nA flaw was found in the Linux kernel's /proc/*/*map* interface. A local,\nunprivileged user could exploit this flaw to cause a denial of service.\n(CVE-2011-3637)\n\nIt was discovered that some import kernel threads can be blocked by a user\nlevel process. An unprivileged local user could exploit this flaw to cause\na denial of service. (CVE-2011-4621)\n\nDan Rosenberg discovered flaws in the linux Rose (X.25 PLP) layer used by\namateur radio. A local user or a remote user on an X.25 network could\nexploit these flaws to execute arbitrary code as root. (CVE-2011-4913)\n\nBen Hutchings discovered several flaws in the Linux Rose (X.25 PLP) layer.\nA local user or a remote user on an X.25 network could exploit these flaws\nto execute arbitrary code as root. (CVE-2011-4914)\n","is_hidden":false,"release_packages":{"natty":[{"name":"linux-ti-omap4","version":"2.6.38-1209.15","description":"Linux kernel for OMAP4","is_source":true},{"name":"linux-image-2.6.38-1209-omap4","version":"2.6.38-1209.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.38-1209.15"}]},"type":"USN","cves_ids":["CVE-2011-0463","CVE-2011-1017","CVE-2011-1020","CVE-2011-1078","CVE-2011-1079","CVE-2011-1080","CVE-2011-1160","CVE-2011-1170","CVE-2011-1171","CVE-2011-1172","CVE-2011-1173","CVE-2011-1180","CVE-2011-1182","CVE-2011-1476","CVE-2011-1477","CVE-2011-1479","CVE-2011-1493","CVE-2011-1494","CVE-2011-1495","CVE-2011-1577","CVE-2011-1581","CVE-2011-1593","CVE-2011-1598","CVE-2011-1745","CVE-2011-1746","CVE-2011-1748","CVE-2011-1770","CVE-2011-1771","CVE-2011-1833","CVE-2011-2022","CVE-2011-2484","CVE-2011-2492","CVE-2011-2493","CVE-2011-2534","CVE-2011-2689","CVE-2011-2699","CVE-2011-2918","CVE-2011-3359","CVE-2011-3637","CVE-2011-4621","CVE-2011-4913","CVE-2011-4914"]}]},{"id":"CVE-2011-1832","published":"2011-08-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nutils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not\nproperly check mountpoint permissions, which allows local users to remove\ndirectories via a umount system call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://www.cve.org/CVERecord?id=CVE-2011-1832"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/732628"],"patches":{"ecryptfs-utils":[]},"tags":{},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"83-0ubuntu3.2.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"83-0ubuntu3.2.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1188-1"],"notices":[{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]}]},{"id":"CVE-2011-1831","published":"2011-08-09T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nutils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not\nproperly check mountpoint permissions, which allows local users to\neffectively replace any directory with a new filesystem, and consequently\ngain privileges, via a mount system call.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1188-1","https://www.cve.org/CVERecord?id=CVE-2011-1831"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/ecryptfs-utils/+bug/732628"],"patches":{"ecryptfs-utils":[]},"tags":{},"packages":[{"name":"ecryptfs-utils","source":"https://ubuntu.com/security/cve?package=ecryptfs-utils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ecryptfs-utils","debian":"https://tracker.debian.org/pkg/ecryptfs-utils","statuses":[{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"83-0ubuntu3.2.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"83-0ubuntu3.2.10.10.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"87-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1188-1"],"notices":[{"id":"USN-1188-1","title":"eCryptfs vulnerabilities","summary":"eCryptfs could be tricked into mounting and unmounting arbitrary locations,\nand possibly disclose confidential information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-08-09T17:26:39.412128","description":"Vasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to mount to arbitrary locations, leading to privilege\nescalation. (CVE-2011-1831)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested mountpoint. A local attacker could\nuse this flaw to unmount to arbitrary locations, leading to a denial of\nservice. (CVE-2011-1832)\n\nVasiliy Kulikov and Dan Rosenberg discovered that eCryptfs incorrectly\nvalidated permissions on the requested source directory. A local attacker\ncould use this flaw to mount an arbitrary directory, possibly leading to\ninformation disclosure. A pending kernel update will provide the other\nhalf of the fix for this issue. (CVE-2011-1833)\n\nDan Rosenberg and Marc Deslauriers discovered that eCryptfs incorrectly\nhandled modifications to the mtab file when an error occurs. A local\nattacker could use this flaw to corrupt the mtab file, and possibly unmount\narbitrary locations, leading to a denial of service. (CVE-2011-1834)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled keys when\nsetting up an encrypted private directory. A local attacker could use this\nflaw to manipulate keys during creation of a new user. (CVE-2011-1835)\n\nMarc Deslauriers discovered that eCryptfs incorrectly handled permissions\nduring recovery. A local attacker could use this flaw to possibly access\nanother user's data during the recovery process. This issue only applied to\nUbuntu 11.04. (CVE-2011-1836)\n\nVasiliy Kulikov discovered that eCryptfs incorrectly handled lock counters.\nA local attacker could use this flaw to possibly overwrite arbitrary files.\nThe default symlink restrictions in Ubuntu 10.10 and 11.04 should protect\nagainst this issue. (CVE-2011-1837)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.1"}],"maverick":[{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"83-0ubuntu3.2.10.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.10.1"}],"natty":[{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","description":"ecryptfs cryptographic filesystem (utilities)","is_source":true},{"name":"ecryptfs-utils","version":"87-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils","version_link":"https://launchpad.net/ubuntu/+source/ecryptfs-utils/87-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2011-1834","CVE-2011-1832","CVE-2011-1836","CVE-2011-1835","CVE-2011-1837","CVE-2011-1831","CVE-2011-1833"]}]},{"id":"CVE-2011-3009","published":"2011-08-05T22:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nRuby before 1.8.6-p114 does not reset the random seed upon forking, which\nmakes it easier for context-dependent attackers to predict the values of\nrandom numbers by leveraging knowledge of the number sequence obtained in a\ndifferent child process, a related issue to CVE-2003-0900.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3009"],"bugs":["http://redmine.ruby-lang.org/issues/show/4338"],"patches":{"ruby1.8":["vendor: https://rhn.redhat.com/errata/RHSA-2011-1581.html"]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.8.7.249-2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2720","published":"2011-08-05T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe autocompletion functionality in GLPI before 0.80.2 does not blacklist\ncertain username and password fields, which allows remote attackers to\nobtain sensitive information via a crafted POST request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-2720"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=726185","https://forge.indepnet.net/issues/3017"],"patches":{"glpi":[]},"tags":{},"packages":[{"name":"glpi","source":"https://ubuntu.com/security/cve?package=glpi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glpi","debian":"https://tracker.debian.org/pkg/glpi","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"0.80.7-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"0.83.1-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"0.83.1-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.83.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.80.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-1340","published":"2011-08-05T21:55:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in\nskins/plone_templates/default_error_message.pt in Plone before 2.5.3 allows\nremote attackers to inject arbitrary web script or HTML via the type_name\nparameter to Members/ipa/createObject.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-1340"],"bugs":["http://dev.plone.org/plone/ticket/6110"],"patches":{"zope-cmfplone":["upstream: http://dev.plone.org/plone/changeset/12262"]},"tags":{},"packages":[{"name":"zope-cmfplone","source":"https://ubuntu.com/security/cve?package=zope-cmfplone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=zope-cmfplone","debian":"https://tracker.debian.org/pkg/zope-cmfplone","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2705","published":"2011-08-05T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe SecureRandom.random_bytes function in lib/securerandom.rb in Ruby\nbefore 1.8.7-p352 and 1.9.x before 1.9.2-p290 relies on PID values for\ninitialization, which makes it easier for context-dependent attackers to\npredict the result string by leveraging knowledge of random strings\nobtained in an earlier process with the same PID.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1377-1","https://www.cve.org/CVERecord?id=CVE-2011-2705"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=722415","http://redmine.ruby-lang.org/issues/4579","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=635878"],"patches":{"ruby1.8":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=32050","vendor: https://rhn.redhat.com/errata/RHSA-2011-1581.html"],"ruby1.9":[],"ruby1.9.1":[]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.8.7.249-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.8.7.299-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.8.7.302-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.8.7.352-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7.352-2","component":null,"pocket":"security"}]},{"name":"ruby1.9","source":"https://ubuntu.com/security/cve?package=ruby1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9","debian":"https://tracker.debian.org/pkg/ruby1.9","statuses":[{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.9.2.290-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.2.290-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1377-1"],"notices":[{"id":"USN-1377-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in ruby1.8.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-28T03:33:06.846369","description":"Drew Yao discovered that the WEBrick HTTP server was vulnerable to cross-site\nscripting attacks when displaying error pages. A remote attacker could use this\nflaw to run arbitrary web script. (CVE-2010-0541)\n\nDrew Yao discovered that Ruby's BigDecimal module did not properly allocate\nmemory on 64-bit platforms. An attacker could use this flaw to cause a denial\nof service or possibly execute arbitrary code with user privileges.\n(CVE-2011-0188)\n\nNicholas Jefferson discovered that the FileUtils.remove_entry_secure method in\nRuby did not properly remove non-empty directories. An attacker could use this\nflaw to possibly delete arbitrary files. (CVE-2011-1004)\n\nIt was discovered that Ruby incorrectly allowed untainted strings to be\nmodified in protective safe levels. An attacker could use this flaw to bypass\nintended access restrictions. (CVE-2011-1005)\n\nEric Wong discovered that Ruby does not properly reseed its pseudorandom number\ngenerator when creating child processes. An attacker could use this flaw to\ngain knowledge of the random numbers used in other Ruby child processes.\n(CVE-2011-2686)\n\nEric Wong discovered that the SecureRandom module in Ruby did not properly seed\nits pseudorandom number generator. An attacker could use this flaw to gain\nknowledge of the random numbers used by another Ruby process with the same\nprocess ID number. (CVE-2011-2705)\n\nAlexander Klink and Julian Wälde discovered that Ruby computed hash values\nwithout restricting the ability to trigger hash collisions predictably. A\nremote attacker could cause a denial of service by crafting values used in hash\ntables. (CVE-2011-4815)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ruby1.8","version":"1.8.7.249-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.249-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.249-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.249-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.249-2ubuntu0.1"}],"maverick":[{"name":"ruby1.8","version":"1.8.7.299-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.299-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.299-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.299-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.299-2ubuntu0.1"}],"natty":[{"name":"ruby1.8","version":"1.8.7.302-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.302-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.302-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.302-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.302-2ubuntu0.1"}],"oneiric":[{"name":"ruby1.8","version":"1.8.7.352-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.352-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.352-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2010-0541","CVE-2011-1004","CVE-2011-4815","CVE-2011-0188","CVE-2011-2686","CVE-2011-2705","CVE-2011-1005"]}]},{"id":"CVE-2011-2686","published":"2011-08-05T00:00:00","updated_at":"2025-08-04T19:24:03.044298+00:00","description":"\nRuby before 1.8.7-p352 does not reset the random seed upon forking, which\nmakes it easier for context-dependent attackers to predict the values of\nrandom numbers by leveraging knowledge of the number sequence obtained in a\ndifferent child process, a related issue to CVE-2003-0900. NOTE: this\nissue exists because of a regression during Ruby 1.8.6 development.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"ruby1.8 only"},{"author":"tyhicks","note":"Simple test case in upstream bug's description"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1377-1","https://www.cve.org/CVERecord?id=CVE-2011-2686"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=722415","http://redmine.ruby-lang.org/issues/show/4338","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=635878"],"patches":{"ruby1.8":["upstream: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=31713"]},"tags":{},"packages":[{"name":"ruby1.8","source":"https://ubuntu.com/security/cve?package=ruby1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby1.8","debian":"https://tracker.debian.org/pkg/ruby1.8","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.8.7.249-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.8.7.299-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.8.7.302-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.8.7.352-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.7.352-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-1377-1"],"notices":[{"id":"USN-1377-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in ruby1.8.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-02-28T03:33:06.846369","description":"Drew Yao discovered that the WEBrick HTTP server was vulnerable to cross-site\nscripting attacks when displaying error pages. A remote attacker could use this\nflaw to run arbitrary web script. (CVE-2010-0541)\n\nDrew Yao discovered that Ruby's BigDecimal module did not properly allocate\nmemory on 64-bit platforms. An attacker could use this flaw to cause a denial\nof service or possibly execute arbitrary code with user privileges.\n(CVE-2011-0188)\n\nNicholas Jefferson discovered that the FileUtils.remove_entry_secure method in\nRuby did not properly remove non-empty directories. An attacker could use this\nflaw to possibly delete arbitrary files. (CVE-2011-1004)\n\nIt was discovered that Ruby incorrectly allowed untainted strings to be\nmodified in protective safe levels. An attacker could use this flaw to bypass\nintended access restrictions. (CVE-2011-1005)\n\nEric Wong discovered that Ruby does not properly reseed its pseudorandom number\ngenerator when creating child processes. An attacker could use this flaw to\ngain knowledge of the random numbers used in other Ruby child processes.\n(CVE-2011-2686)\n\nEric Wong discovered that the SecureRandom module in Ruby did not properly seed\nits pseudorandom number generator. An attacker could use this flaw to gain\nknowledge of the random numbers used by another Ruby process with the same\nprocess ID number. (CVE-2011-2705)\n\nAlexander Klink and Julian Wälde discovered that Ruby computed hash values\nwithout restricting the ability to trigger hash collisions predictably. A\nremote attacker could cause a denial of service by crafting values used in hash\ntables. (CVE-2011-4815)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"ruby1.8","version":"1.8.7.249-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.249-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.249-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.249-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.249-2ubuntu0.1"}],"maverick":[{"name":"ruby1.8","version":"1.8.7.299-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.299-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.299-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.299-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.299-2ubuntu0.1"}],"natty":[{"name":"ruby1.8","version":"1.8.7.302-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.302-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.302-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.302-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.302-2ubuntu0.1"}],"oneiric":[{"name":"ruby1.8","version":"1.8.7.352-2ubuntu0.1","description":"Interpreter of object-oriented scripting language Ruby 1.8","is_source":true},{"name":"ruby1.8","version":"1.8.7.352-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu0.1"},{"name":"libruby1.8","version":"1.8.7.352-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.8","version_link":"https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2010-0541","CVE-2011-1004","CVE-2011-4815","CVE-2011-0188","CVE-2011-2686","CVE-2011-2705","CVE-2011-1005"]}]}],"offset":70860,"limit":20,"total_results":79316}