{"cves":[{"id":"CVE-2010-2762","published":"2010-09-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW)\nimplementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x\nbefore 3.1.3 does not properly restrict objects at the end of scope chains,\nwhich allows remote attackers to execute arbitrary JavaScript code with\nchrome privileges via vectors related to a chrome privileged object and a\nchain ending in an outer object.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages for\nbuilds that use the system xulrunner, and firefox source packages for those\nthat use a static build\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS (system xul)\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS (system xul)\nxulrunner-1.9: (ignored) reverse dependencies no longer process web content\nxulrunner-1.9.1: (ignored) reverese dependencies no longer process web content\nxulrunner-1.9.2: system xul for reverese dependencies that process web content\nfirefox: Ubuntu 6.06 LTS (static build)\nfirefox: Ubuntu 10.04 LTS and higher (static build of 3.6.x or higher)\nfirefox-3.0: Ubuntu 8.04 LTS, 9.04 (static build of 3.6.x)\nfirefox-3.5: Ubuntu 9.04 (ignored, uses system xul 1.9.1. Use 3.0 instead)\nfirefox-3.5: Ubuntu 9.10 (static build of 3.6.x)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-975-1","https://www.cve.org/CVERecord?id=CVE-2010-2762"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"firefox-3.5":[],"xulrunner-1.9.2":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.9","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"firefox-3.5","source":"https://ubuntu.com/security/cve?package=firefox-3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.5","debian":"https://tracker.debian.org/pkg/firefox-3.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.5.12+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.3","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.2.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-975-1"],"notices":[{"id":"USN-975-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to crash or possibly run programs as your login if it\nopened a specially crafted file or website.\n","instructions":"After a standard system update you need to restart Firefox and any\napplication that use Xulrunner to make all the necessary changes.\n","references":[],"published":"2010-09-08T21:14:45.016466","description":"Several dangling pointer vulnerabilities were discovered in Firefox. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,\nCVE-2010-3167)\n\nBlake Kaplan and Michal Zalewski discovered several weaknesses in the\nXPCSafeJSObjectWrapper (SJOW) security wrapper. If a user were tricked into\nviewing a malicious site, a remote attacker could use this to run arbitrary\nJavaScript with chrome privileges. (CVE-2010-2762)\n\nMatt Haggard discovered that Firefox did not honor same-origin policy when\nprocessing the statusText property of an XMLHttpRequest object. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to gather information about servers on internal private networks.\n(CVE-2010-2764)\n\nChris Rohlf discovered an integer overflow when Firefox processed the HTML\nframeset element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2765)\n\nSeveral issues were discovered in the browser engine. If a user were\ntricked into viewing a malicious site, a remote attacker could use this to\ncrash the browser or possibly run arbitrary code as the user invoking the\nprogram. (CVE-2010-2766, CVE-2010-3168)\n\nDavid Huang and Collin Jackson discovered that the tag could\noverride the charset of a framed HTML document in another origin. An\nattacker could utilize this to perform cross-site scripting attacks.\n(CVE-2010-2768)\n\nPaul Stone discovered that with designMode enabled an HTML selection\ncontaining JavaScript could be copied and pasted into a document and have\nthe JavaScript execute within the context of the site where the code was\ndropped. An attacker could utilize this to perform cross-site scripting\nattacks. (CVE-2010-2769)\n\nA buffer overflow was discovered in Firefox when processing text runs. If a\nuser were tricked into viewing a malicious site, a remote attacker could\nuse this to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-3166)\n\nPeter Van der Beken, Jason Oster, Jesse Ruderman, Igor Bukanov, Jeff\nWalden, Gary Kwong and Olli Pettay discovered several flaws in the\nbrowser engine. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-3169)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.9+build1+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.9+build1+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.9+build1+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.9+build1+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.9+build1+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1"}],"karmic":[{"name":"firefox-3.5","version":"3.6.9+build1+nobinonly-0ubuntu0.9.10.2","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.5","version":"3.6.9+build1+nobinonly-0ubuntu0.9.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.9+build1+nobinonly-0ubuntu0.9.10.2"},{"name":"xulrunner-1.9.1","version":"1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2010-2764","CVE-2010-2762","CVE-2010-2767","CVE-2010-2768","CVE-2010-2769","CVE-2010-3167","CVE-2010-2765","CVE-2010-3169","CVE-2010-3168","CVE-2010-2766","CVE-2010-2760","CVE-2010-3166"]}]},{"id":"CVE-2010-2760","published":"2010-09-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUse-after-free vulnerability in the nsTreeSelection function in Mozilla\nFirefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and\n3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers\nto execute arbitrary code via vectors involving a XUL tree selection,\nrelated to a \"dangling pointer vulnerability.\" NOTE: this issue exists\nbecause of an incomplete fix for CVE-2010-2753.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"CVEs in Firefox are tracked in the xulrunner source packages for\nbuilds that use the system xulrunner, and firefox source packages for those\nthat use a static build\nxulrunner (1.8.0): firefox (1.5) - Ubuntu 6.06 LTS (system xul)\nxulrunner (1.8.1): firefox (2.0) - Ubuntu 6.10 - 8.04 LTS (system xul)\nxulrunner-1.9: (ignored) reverse dependencies no longer process web content\nxulrunner-1.9.1: (ignored) reverese dependencies no longer process web content\nxulrunner-1.9.2: system xul for reverese dependencies that process web content\nfirefox: Ubuntu 6.06 LTS (static build)\nfirefox: Ubuntu 10.04 LTS and higher (static build of 3.6.x or higher)\nfirefox-3.0: Ubuntu 8.04 LTS, 9.04 (static build of 3.6.x)\nfirefox-3.5: Ubuntu 9.04 (ignored, uses system xul 1.9.1. Use 3.0 instead)\nfirefox-3.5: Ubuntu 9.10 (static build of 3.6.x)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-978-1","https://ubuntu.com/security/notices/USN-975-1","https://www.cve.org/CVERecord?id=CVE-2010-2760"],"bugs":[""],"patches":{"firefox":[],"firefox-3.0":[],"firefox-3.5":[],"xulrunner-1.9.1":[],"xulrunner-1.9.2":[],"seamonkey":[],"thunderbird":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"}]},{"name":"firefox-3.0","source":"https://ubuntu.com/security/cve?package=firefox-3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.0","debian":"https://tracker.debian.org/pkg/firefox-3.0","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"firefox-3.5","source":"https://ubuntu.com/security/cve?package=firefox-3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-3.5","debian":"https://tracker.debian.org/pkg/firefox-3.5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"3.5.12+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"3.6.9+build1+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"Ubuntu source uses 3.6.x","component":null,"pocket":"security"}]},{"name":"seamonkey","source":"https://ubuntu.com/security/cve?package=seamonkey","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=seamonkey","debian":"https://tracker.debian.org/pkg/seamonkey","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.0.8+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.0.7+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.0.7+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"2.0.7+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.7","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"3.0.7+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"3.1.3+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"3.1.3+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.7, 3.1.3","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.1","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.1","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.1.12+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1.12","component":null,"pocket":"security"}]},{"name":"xulrunner-1.9.2","source":"https://ubuntu.com/security/cve?package=xulrunner-1.9.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xulrunner-1.9.2","debian":"https://tracker.debian.org/pkg/xulrunner-1.9.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"released","description":"1.9.2.9+build1+nobinonly-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.2.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-978-1","USN-975-1"],"notices":[{"id":"USN-978-1","title":"Thunderbird vulnerabilities","summary":"Thunderbird could be made to crash or possibly run programs as your login\nif it opened a specially crafted file or website.\n","instructions":"After a standard system update you need to restart Thunderbird to make\nall the necessary changes.\n","references":[],"published":"2010-09-08T21:13:03.485330","description":"Several dangling pointer vulnerabilities were discovered in Thunderbird. An\nattacker could exploit this to crash Thunderbird or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,\nCVE-2010-3167)\n\nIt was discovered that the XPCSafeJSObjectWrapper (SJOW) security wrapper\ndid not always honor the same-origin policy. If JavaScript was enabled, an\nattacker could exploit this to run untrusted JavaScript from other domains.\n(CVE-2010-2763)\n\nMatt Haggard discovered that Thunderbird did not honor same-origin policy\nwhen processing the statusText property of an XMLHttpRequest object. If a\nuser were tricked into viewing a malicious site, a remote attacker could\nuse this to gather information about servers on internal private networks.\n(CVE-2010-2764)\n\nChris Rohlf discovered an integer overflow when Thunderbird processed the\nHTML frameset element. If a user were tricked into viewing a malicious\nsite, a remote attacker could use this to crash Thunderbird or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2765)\n\nSeveral issues were discovered in the browser engine. If a user were\ntricked into viewing a malicious site, a remote attacker could use this to\ncrash Thunderbird or possibly run arbitrary code as the user invoking the\nprogram. (CVE-2010-2766, CVE-2010-3168)\n\nDavid Huang and Collin Jackson discovered that the tag could\noverride the charset of a framed HTML document in another origin. An\nattacker could utilize this to perform cross-site scripting attacks.\n(CVE-2010-2768)\n\nPaul Stone discovered that with designMode enabled an HTML selection\ncontaining JavaScript could be copied and pasted into a document and have\nthe JavaScript execute within the context of the site where the code was\ndropped. If JavaScript was enabled, an attacker could utilize this to\nperform cross-site scripting attacks. (CVE-2010-2769)\n\nA buffer overflow was discovered in Thunderbird when processing text runs.\nIf a user were tricked into viewing a malicious site, a remote attacker\ncould use this to crash Thunderbird or possibly run arbitrary code as the\nuser invoking the program. (CVE-2010-3166)\n\nPeter Van der Beken, Jason Oster, Jesse Ruderman, Igor Bukanov, Jeff\nWalden, Gary Kwong and Olli Pettay discovered several flaws in the\nbrowser engine. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash Thunderbird or possibly run\narbitrary code as the user invoking the program. (CVE-2010-3169)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"thunderbird","version":"3.0.7+build1+nobinonly-0ubuntu0.10.04.1","description":"mail/news client with RSS and integrated spam filter support","is_source":true},{"name":"thunderbird","version":"3.0.7+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/thunderbird","version_link":"https://launchpad.net/ubuntu/+source/thunderbird/3.0.7+build1+nobinonly-0ubuntu0.10.04.1"}]},"type":"USN","cves_ids":["CVE-2010-2763","CVE-2010-3169","CVE-2010-2765","CVE-2010-2767","CVE-2010-3166","CVE-2010-2760","CVE-2010-3168","CVE-2010-3167","CVE-2010-2766","CVE-2010-2768","CVE-2010-2769","CVE-2010-2764"]},{"id":"USN-975-1","title":"Firefox and Xulrunner vulnerabilities","summary":"Firefox could be made to crash or possibly run programs as your login if it\nopened a specially crafted file or website.\n","instructions":"After a standard system update you need to restart Firefox and any\napplication that use Xulrunner to make all the necessary changes.\n","references":[],"published":"2010-09-08T21:14:45.016466","description":"Several dangling pointer vulnerabilities were discovered in Firefox. An\nattacker could exploit this to crash the browser or possibly run arbitrary\ncode as the user invoking the program. (CVE-2010-2760, CVE-2010-2767,\nCVE-2010-3167)\n\nBlake Kaplan and Michal Zalewski discovered several weaknesses in the\nXPCSafeJSObjectWrapper (SJOW) security wrapper. If a user were tricked into\nviewing a malicious site, a remote attacker could use this to run arbitrary\nJavaScript with chrome privileges. (CVE-2010-2762)\n\nMatt Haggard discovered that Firefox did not honor same-origin policy when\nprocessing the statusText property of an XMLHttpRequest object. If a user\nwere tricked into viewing a malicious site, a remote attacker could use\nthis to gather information about servers on internal private networks.\n(CVE-2010-2764)\n\nChris Rohlf discovered an integer overflow when Firefox processed the HTML\nframeset element. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-2765)\n\nSeveral issues were discovered in the browser engine. If a user were\ntricked into viewing a malicious site, a remote attacker could use this to\ncrash the browser or possibly run arbitrary code as the user invoking the\nprogram. (CVE-2010-2766, CVE-2010-3168)\n\nDavid Huang and Collin Jackson discovered that the tag could\noverride the charset of a framed HTML document in another origin. An\nattacker could utilize this to perform cross-site scripting attacks.\n(CVE-2010-2768)\n\nPaul Stone discovered that with designMode enabled an HTML selection\ncontaining JavaScript could be copied and pasted into a document and have\nthe JavaScript execute within the context of the site where the code was\ndropped. An attacker could utilize this to perform cross-site scripting\nattacks. (CVE-2010-2769)\n\nA buffer overflow was discovered in Firefox when processing text runs. If a\nuser were tricked into viewing a malicious site, a remote attacker could\nuse this to crash the browser or possibly run arbitrary code as the user\ninvoking the program. (CVE-2010-3166)\n\nPeter Van der Beken, Jason Oster, Jesse Ruderman, Igor Bukanov, Jeff\nWalden, Gary Kwong and Olli Pettay discovered several flaws in the\nbrowser engine. If a user were tricked into viewing a malicious site, a\nremote attacker could use this to crash the browser or possibly run\narbitrary code as the user invoking the program. (CVE-2010-3169)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.8.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.9+build1+nobinonly-0ubuntu0.8.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1"}],"lucid":[{"name":"firefox","version":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"abrowser","version":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.9+build1+nobinonly-0ubuntu0.10.04.1"},{"name":"firefox","version":"3.6.9+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox","version_link":"https://launchpad.net/ubuntu/+source/firefox/3.6.9+build1+nobinonly-0ubuntu0.10.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1"}],"jaunty":[{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.0","version":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.9+build1+nobinonly-0ubuntu0.9.04.1"},{"name":"abrowser","version":"3.6.9+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.0","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.0/3.6.9+build1+nobinonly-0ubuntu0.9.04.1"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1"}],"karmic":[{"name":"firefox-3.5","version":"3.6.9+build1+nobinonly-0ubuntu0.9.10.2","description":"Safe and easy web browser from Mozilla","is_source":true},{"name":"xulrunner-1.9.1","version":"1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2","description":"XUL + XPCOM application runner","is_source":true},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1","description":"XUL + XPCOM application runner","is_source":true},{"name":"firefox-3.5","version":"3.6.9+build1+nobinonly-0ubuntu0.9.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/firefox-3.5","version_link":"https://launchpad.net/ubuntu/+source/firefox-3.5/3.6.9+build1+nobinonly-0ubuntu0.9.10.2"},{"name":"xulrunner-1.9.1","version":"1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.1/1.9.1.12+build1+nobinonly-0ubuntu0.9.10.2"},{"name":"xulrunner-1.9.2","version":"1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2","version_link":"https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1"}]},"type":"USN","cves_ids":["CVE-2010-2764","CVE-2010-2762","CVE-2010-2767","CVE-2010-2768","CVE-2010-2769","CVE-2010-3167","CVE-2010-2765","CVE-2010-3169","CVE-2010-3168","CVE-2010-2766","CVE-2010-2760","CVE-2010-3166"]}]},{"id":"CVE-2010-2521","published":"2010-09-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nMultiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in\nthe NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers\nto cause a denial of service (panic) or possibly execute arbitrary code via\na crafted NFSv4 compound WRITE request, related to the read_buf and\nnfsd4_decode_compound functions.","ubuntu_description":"\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2521"],"bugs":[""],"patches":{"linux-source-2.6.15":["dapper: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2521/patches/dapper/linux/0001-nfsd4-bug-in-read_buf.txt"],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=2bc3c1179c781b359d4f2f3439cb3df72afc17fc","hardy: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2521/patches/hardy/linux/0001-nfsd4-bug-in-read_buf.txt","jaunty: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2521/patches/jaunty/linux/0001-nfsd4-bug-in-read_buf.txt","karmic: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2521/patches/karmic/linux/0001-nfsd4-bug-in-read_buf.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.80","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-23.37","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34-rc6","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.89","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2248","published":"2010-09-07T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nfs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before\n2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via\nan SMB response packet with an invalid CountHigh value, as demonstrated by\na response from an OS/2 server, related to the CIFSSMBWrite and\nCIFSSMBWrite2 functions.","ubuntu_description":"\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2010/06/28/1","https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2248"],"bugs":[""],"patches":{"linux-source-2.6.15":["dapper: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2248/patches/dapper/linux/0001-cifs-Fix-a-kernel-BUG-with-remote-OS-2-server-try-3.txt"],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=6513a81e9325d712f1bfb9a1d7b750134e49ff18","hardy: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2248/patches/hardy/linux/0001-cifs-Fix-a-kernel-BUG-with-remote-OS-2-server-try-3.txt","jaunty: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2248/patches/jaunty/linux/0001-cifs-Fix-a-kernel-BUG-with-remote-OS-2-server-try-3.txt","karmic: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2248/patches/karmic/linux/0001-cifs-Fix-a-kernel-BUG-with-remote-OS-2-server-try-3.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.80","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-23.37","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.34-rc4","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"released","description":"2.6.15-55.89","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2532","published":"2010-09-03T20:00:00","updated_at":"2025-08-04T19:23:46.919224+00:00","description":"\nlxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and\nother platforms, does not lock the screen when the Suspend or Hibernate\nbutton is pressed, which might make it easier for physically proximate\nattackers to access an unattended laptop via a resume action. NOTE: there\nis no general agreement that this is a vulnerability, because separate\ncontrol over locking can be an equally secure, or more secure, behavior in\nsome threat environments.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2532"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=591409","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2532","https://bugzilla.novell.com/show_bug.cgi?id=622083"],"patches":{"lxsession":[]},"tags":{},"packages":[{"name":"lxsession","source":"https://ubuntu.com/security/cve?package=lxsession","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxsession","debian":"https://tracker.debian.org/pkg/lxsession","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"0.4.4-3","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"0.4.4-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3205","published":"2010-09-03T18:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nPHP remote file inclusion vulnerability in index.php in Textpattern CMS\n4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in\nthe inc parameter.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"PoC: http://packetstormsecurity.org/1008-exploits/textpattern-rfi.txt"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3205"],"bugs":[""],"patches":{"textpattern":[]},"tags":{},"packages":[{"name":"textpattern","source":"https://ubuntu.com/security/cve?package=textpattern","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=textpattern","debian":"https://tracker.debian.org/pkg/textpattern","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2954","published":"2010-09-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe irda_bind function in net/irda/af_irda.c in the Linux kernel before\n2.6.36-rc3-next-20100901 does not properly handle failure of the\nirda_open_tsap function, which allows local users to cause a denial of\nservice (NULL pointer dereference and panic) and possibly have unspecified\nother impact via multiple unsuccessful calls to bind on an AF_IRDA (aka\nPF_IRDA) socket.","ubuntu_description":"\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://ubuntu.com/security/notices/USN-1093-1","https://ubuntu.com/security/notices/USN-1119-1","https://www.cve.org/CVERecord?id=CVE-2010-2954"],"bugs":[""],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=628e300cccaa628d8fb92aa28cb7530a3d5f2257","hardy: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2954/patches/hardy/linux/0001-irda-Correctly-clean-up-self-ias_obj-on-irda_bind-fail.txt","jaunty: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2954/patches/jaunty/linux/0001-irda-Correctly-clean-up-self-ias_obj-on-irda_bind-fail.txt","karmic: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2954/patches/karmic/linux/0001-irda-Correctly-clean-up-self-ias_obj-on-irda_bind-fail.txt","lucid: http://chinstrap.ubuntu.com/~sconklin/CVEs/CVE-2010-2954/patches/lucid/linux/0001-irda-Correctly-clean-up-self-ias_obj-on-irda_bind-fail.txt"],"linux-mvl-dove":[],"linux-ec2":[],"linux-fsl-imx51":[],"linux-lts-backport-maverick":[],"linux-ti-omap4":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.80","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-25.45","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]},{"name":"linux-mvl-dove","source":"https://ubuntu.com/security/cve?package=linux-mvl-dove","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mvl-dove","debian":"https://tracker.debian.org/pkg/linux-mvl-dove","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-216.33","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.32-416.33","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"2.6.35-903.22","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.36~rc4","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1119-1","USN-1000-1","USN-1074-2","USN-1093-1"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1119-1","title":"Linux kernel (OMAP4) vulnerabilities","summary":"Multiple security flaws have been fixed in the OMAP4 port of the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-04-20T19:57:52.940545","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nNelson Elhage discovered that Econet did not correctly handle AUN packets\nover UDP. A local attacker could send specially crafted traffic to crash\nthe system, leading to a denial of service. (CVE-2010-4342)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nDan Rosenberg discovered that IRDA did not correctly check the size of\nbuffers. On non-x86 systems, a local attacker could exploit this to read\nkernel heap memory, leading to a loss of privacy. (CVE-2010-4529)\n","is_hidden":false,"release_packages":{"maverick":[{"name":"linux-ti-omap4","version":"2.6.35-903.22","description":"Linux kernel for OMAP4 devices","is_source":true},{"name":"linux-image-2.6.35-903-omap4","version":"2.6.35-903.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4","version_link":"https://launchpad.net/ubuntu/+source/linux-ti-omap4/2.6.35-903.22"}]},"type":"USN","cves_ids":["CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3437","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3861","CVE-2010-3865","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4079","CVE-2010-4158","CVE-2010-4164","CVE-2010-4165","CVE-2010-4249","CVE-2010-4258","CVE-2010-4342","CVE-2010-4346","CVE-2010-4527","CVE-2010-4529"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1093-1","title":"Linux Kernel vulnerabilities (Marvell Dove)","summary":"An attacker could send crafted input to the kernel and cause it to\ncrash.\n","instructions":"ATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":["CVE-2010-NNN2"],"published":"2011-03-25T19:57:30.379392","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nThomas Pollet discovered that the RDS network protocol did not check\ncertain iovec buffers. A local attacker could exploit this to crash the\nsystem or possibly execute arbitrary code as the root user. (CVE-2010-3865)\n\nDan Rosenberg discovered that the Linux kernel X.25 implementation\nincorrectly parsed facilities. A remote attacker could exploit this to\ncrash the kernel, leading to a denial of service. (CVE-2010-3873)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nVasiliy Kulikov discovered that the Linux kernel X.25 implementation did\nnot correctly clear kernel memory. A local attacker could exploit this to\nread kernel stack memory, leading to a loss of privacy. (CVE-2010-3875)\n\nVasiliy Kulikov discovered that the Linux kernel sockets implementation did\nnot properly initialize certain structures. A local attacker could exploit\nthis to read kernel stack memory, leading to a loss of privacy.\n(CVE-2010-3876)\n\nVasiliy Kulikov discovered that the TIPC interface did not correctly\ninitialize certain structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-3877)\n\nNelson Elhage discovered that the Linux kernel IPv4 implementation did not\nproperly audit certain bytecodes in netlink messages. A local attacker\ncould exploit this to cause the kernel to hang, leading to a denial of\nservice. (CVE-2010-3880)\n\nVasiliy Kulikov discovered that kvm did not correctly clear memory. A local\nattacker could exploit this to read portions of the kernel stack, leading\nto a loss of privacy. (CVE-2010-3881)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that multiple terminal ioctls did not correctly\ninitialize structure memory. A local attacker could exploit this to read\nportions of kernel stack memory, leading to a loss of privacy.\n(CVE-2010-4075)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nDan Rosenberg discovered that the semctl syscall did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4083)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered that the SCSI subsystem did not correctly validate\niov segments. A local attacker with access to a SCSI device could send\nspecially crafted requests to crash the system, leading to a denial of\nservice. (CVE-2010-4163, CVE-2010-4668)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nIt was discovered that multithreaded exec did not handle CPU timers\ncorrectly. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-4248)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKrishna Gudipati discovered that the bfa adapter driver did not correctly\ninitialize certain structures. A local attacker could read files in /sys to\ncrash the system, leading to a denial of service. (CVE-2010-4343)\n\nTavis Ormandy discovered that the install_special_mapping function could\nbypass the mmap_min_addr restriction. A local attacker could exploit this\nto mmap 4096 bytes below the mmap_min_addr area, possibly improving the\nchances of performing NULL pointer dereference attacks. (CVE-2010-4346)\n\nIt was discovered that the ICMP stack did not correctly handle certain\nunreachable messages. If a remote attacker were able to acquire a socket\nlock, they could send specially crafted traffic that would crash the\nsystem, leading to a denial of service. (CVE-2010-4526)\n\nDan Rosenberg discovered that the OSS subsystem did not handle name\ntermination correctly. A local attacker could exploit this crash the system\nor gain root privileges. (CVE-2010-4527)\n\nAn error was reported in the kernel's ORiNOCO wireless driver's handling of\nTKIP countermeasures. This reduces the amount of time an attacker needs\nbreach a wireless network using WPA+TKIP for security. (CVE-2010-4648)\n\nDan Carpenter discovered that the Infiniband driver did not correctly\nhandle certain requests. A local user could exploit this to crash the\nsystem or potentially gain root privileges. (CVE-2010-4649, CVE-2011-1044)\n\nAn error was discovered in the kernel's handling of CUSE (Character device\nin Userspace). A local attacker might exploit this flaw to escalate\nprivilege, if access to /dev/cuse has been modified to allow non-root\nusers. (CVE-2010-4650)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nKees Cook discovered that the IOWarrior USB device driver did not correctly\ncheck certain size fields. A local attacker with physical access could plug\nin a specially crafted USB device to crash the system or potentially gain\nroot privileges. (CVE-2010-4656)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n\nA flaw was found in the kernel's Integrity Measurement Architecture (IMA).\nChanges made by an attacker might not be discovered by IMA, if SELinux was\ndisabled, and a new IMA rule was loaded. (CVE-2011-0006)\n\nDan Carpenter discovered that the TTPCI DVB driver did not check certain\nvalues during an ioctl. If the dvb-ttpci module was loaded, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice, or possibly gain root privileges. (CVE-2011-0521)\n\nRafael Dominguez Vega discovered that the caiaq Native Instruments USB\ndriver did not correctly validate string lengths. A local attacker with\nphysical access could plug in a specially crafted USB device to crash the\nsystem or potentially gain root privileges. (CVE-2011-0712)\n\nTimo Warns discovered that MAC partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system or potentially gain\nroot privileges. (CVE-2011-1010)\n\nTimo Warns discovered that LDM partition parsing routines did not correctly\ncalculate block counts. A local attacker with physical access could plug in\na specially crafted block device to crash the system, leading to a denial\nof service. (CVE-2011-1012)\n\nNelson Elhage discovered that the epoll subsystem did not correctly handle\ncertain structures. A local attacker could create malicious requests that\nwould hang the system, leading to a denial of service. (CVE-2011-1082)\n\nJohan Hovold discovered that the DCCP network stack did not correctly\nhandle certain packet combinations. A remote attacker could send specially\ncrafted network traffic that would crash the system, leading to a denial of\nservice. (CVE-2011-1093)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-mvl-dove","version":"2.6.32-216.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-216-dove","version":"2.6.32-216.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-216.33"}],"maverick":[{"name":"linux-mvl-dove","version":"2.6.32-416.33","description":"Block storage devices (udeb)","is_source":true},{"name":"linux-image-2.6.32-416-dove","version":"2.6.32-416.33","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove","version_link":"https://launchpad.net/ubuntu/+source/linux-mvl-dove/2.6.32-416.33"}]},"type":"USN","cves_ids":["CVE-2010-2478","CVE-2010-2942","CVE-2010-2943","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3865","CVE-2010-3873","CVE-2010-3874","CVE-2010-3875","CVE-2010-3876","CVE-2010-3877","CVE-2010-3880","CVE-2010-3881","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4075","CVE-2010-4079","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4083","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4163","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4248","CVE-2010-4249","CVE-2010-4258","CVE-2010-4343","CVE-2010-4346","CVE-2010-4526","CVE-2010-4527","CVE-2010-4648","CVE-2010-4649","CVE-2010-4650","CVE-2010-4655","CVE-2010-4656","CVE-2010-4668","CVE-2011-0006","CVE-2011-0521","CVE-2011-0712","CVE-2011-1010","CVE-2011-1012","CVE-2011-1044","CVE-2011-1082","CVE-2011-1093"]}]},{"id":"CVE-2010-2226","published":"2010-09-03T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before\n2.6.35 does not properly check the file descriptors passed to the SWAPEXT\nioctl, which allows local users to leverage write access and obtain read\naccess by swapping one file into another file.","ubuntu_description":"\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy.","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://marc.info/?l=oss-security&m=127677135609357&w=2","https://ubuntu.com/security/notices/USN-1000-1","https://ubuntu.com/security/notices/USN-1074-1","https://ubuntu.com/security/notices/USN-1074-2","https://ubuntu.com/security/notices/USN-1083-1","https://www.cve.org/CVERecord?id=CVE-2010-2226"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=605158"],"patches":{"linux-source-2.6.15":[],"linux":["upstream: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=1817176a86352f65210139d4c794ad2d19fc6b63","hardy: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2226/patches/hardy/linux/0001-xfs-prevent-swapext-from-operating-on-write-only-files.txt","jaunty: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2226/patches/jaunty/linux/0001-xfs-prevent-swapext-from-operating-on-write-only-files.txt","karmic: http://chinstrap.ubuntu.com/~bradf/CVEs/CVE-2010-2226/patches/karmic/linux/0001-xfs-prevent-swapext-from-operating-on-write-only-files.txt"],"linux-fsl-imx51":[],"linux-ec2":[],"linux-lts-backport-maverick":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-28.80","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-19.66","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-22.67","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35~rc4","component":null,"pocket":"security"}]},{"name":"linux-ec2","source":"https://ubuntu.com/security/cve?package=linux-ec2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ec2","debian":"https://tracker.debian.org/pkg/linux-ec2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-307.21","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.32-309.18","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35~rc4","component":null,"pocket":"security"}]},{"name":"linux-fsl-imx51","source":"https://ubuntu.com/security/cve?package=linux-fsl-imx51","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fsl-imx51","debian":"https://tracker.debian.org/pkg/linux-fsl-imx51","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"2.6.31-112.30","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.31-608.22","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35~rc4","component":null,"pocket":"security"}]},{"name":"linux-lts-backport-maverick","source":"https://ubuntu.com/security/cve?package=linux-lts-backport-maverick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-backport-maverick","debian":"https://tracker.debian.org/pkg/linux-lts-backport-maverick","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"2.6.35-25.44~lucid1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35~rc4","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.35~rc4","component":null,"pocket":"security"}]}],"notices_ids":["USN-1074-1","USN-1083-1","USN-1000-1","USN-1074-2"],"notices":[{"id":"USN-1074-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2011-02-25T23:58:47.343176","description":"Al Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nGael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory\nmanager did not properly handle when applications grow stacks into adjacent\nmemory regions. A local attacker could exploit this to gain control of\ncertain applications, potentially leading to privilege escalation, as\ndemonstrated in attacks against the X server. (CVE-2010-2240)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy. Only\nUbuntu 9.10 was affected. (CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nKees Cook discovered that under certain situations the ioctl subsystem for\nDRM did not properly sanitize its arguments. A local attacker could exploit\nthis to read previously freed kernel memory, leading to a loss of privacy.\n(CVE-2010-2803)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nBen Hawkes discovered an integer overflow in the Controller Area Network\n(CVE-2010-2959)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\nUbuntu 10.10 was not affected. (CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"linux-fsl-imx51","version":"2.6.31-112.30","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-112-imx51","version":"2.6.31-112.30","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-112.30"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2240","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2803","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2959","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]},{"id":"USN-1083-1","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2011-03-03T00:49:49.770755","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nGleb Napatov discovered that KVM did not correctly check certain privileged\noperations. A local attacker with access to a guest kernel could exploit\nthis to crash the host system, leading to a denial of service.\n(CVE-2010-0435)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2537, CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nDan Rosenberg discovered that the Linux kernel TIPC implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to gain root privileges. (CVE-2010-3859)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nDan Rosenberg discovered that the CAN protocol on 64bit systems did not\ncorrectly calculate the size of certain buffers. A local attacker could\nexploit this to crash the system or possibly execute arbitrary code as the\nroot user. (CVE-2010-3874)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the RME Hammerfall DSP audio interface driver\ndid not correctly clear kernel memory. A local attacker could exploit this\nto read kernel stack memory, leading to a loss of privacy. (CVE-2010-4080,\nCVE-2010-4081)\n\nDan Rosenberg discovered that the VIA video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4082)\n\nJames Bottomley discovered that the ICP vortex storage array controller\ndriver did not validate certain sizes. A local attacker on a 64bit system\ncould exploit this to crash the kernel, leading to a denial of service.\n(CVE-2010-4157)\n\nDan Rosenberg discovered that the socket filters did not correctly\ninitialize structure memory. A local attacker could create malicious\nfilters to read portions of kernel stack memory, leading to a loss of\nprivacy. (CVE-2010-4158)\n\nDan Rosenberg discovered that the Linux kernel L2TP implementation\ncontained multiple integer signedness errors. A local attacker could\nexploit this to to crash the kernel, or possibly gain root privileges.\n(CVE-2010-4160)\n\nDan Rosenberg discovered that certain iovec operations did not calculate\npage counts correctly. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4162)\n\nDan Rosenberg discovered multiple flaws in the X.25 facilities parsing. If\na system was using X.25, a remote attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4164)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nDan Rosenberg discovered that the RDS protocol did not correctly check\nioctl arguments. A local attacker could exploit this to crash the system,\nleading to a denial of service. (CVE-2010-4175)\n\nAlan Cox discovered that the HCI UART driver did not correctly check if a\nwrite operation was available. If the mmap_min-addr sysctl was changed from\nthe Ubuntu default to a value of 0, a local attacker could exploit this\nflaw to gain root privileges. (CVE-2010-4242)\n\nBrad Spengler discovered that the kernel did not correctly account for\nuserspace memory allocations during exec() calls. A local attacker could\nexploit this to consume all system memory, leading to a denial of service.\n(CVE-2010-4243)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nIt was discovered that named pipes did not correctly handle certain fcntl\ncalls. A local attacker could exploit this to crash the system, leading to\na denial of service. (CVE-2010-4256)\n\nNelson Elhage discovered that the kernel did not correctly handle process\ncleanup after triggering a recoverable kernel bug. If a local attacker were\nable to trigger certain kinds of kernel bugs, they could create a specially\ncrafted process to gain root privileges. (CVE-2010-4258)\n\nKees Cook discovered that some ethtool functions did not correctly clear\nheap memory. A local attacker with CAP_NET_ADMIN privileges could exploit\nthis to read portions of kernel heap memory, leading to a loss of privacy.\n(CVE-2010-4655)\n\nFrank Arnold discovered that the IGMP protocol did not correctly parse\ncertain packets. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2011-0709)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-lts-backport-maverick","version":"2.6.35-25.44~lucid1","description":"Linux kernel, Maverick backport to Lucid LTS","is_source":true},{"name":"linux-image-2.6.35-25-virtual","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-server","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic-pae","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"},{"name":"linux-image-2.6.35-25-generic","version":"2.6.35-25.44~lucid1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-backport-maverick/2.6.35-25.44~lucid1"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-0435","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2537","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2960","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3859","CVE-2010-3861","CVE-2010-3874","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4080","CVE-2010-4081","CVE-2010-4082","CVE-2010-4157","CVE-2010-4158","CVE-2010-4160","CVE-2010-4162","CVE-2010-4164","CVE-2010-4165","CVE-2010-4169","CVE-2010-4175","CVE-2010-4242","CVE-2010-4243","CVE-2010-4249","CVE-2010-4256","CVE-2010-4258","CVE-2010-4655","CVE-2011-0709"]},{"id":"USN-1000-1","title":"Linux kernel vulnerabilities","summary":"Multiple security issues fixed.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2010-10-19T17:50:10.603371","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered a flaw in gfs2 file system's handling of acls\n(access control lists). An unprivileged local attacker could exploit this\nflaw to gain access or execute any file stored in the gfs2 file system.\n(CVE-2010-2525)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nTavis Ormandy discovered that the session keyring did not correctly check\nfor its parent. On systems without a default session keyring, a local\nattacker could exploit this to crash the system, leading to a denial of\nservice. (CVE-2010-2960)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-ec2","version":"2.6.32-309.18","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.32-25.45","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.32-25-powerpc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-lpia","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-386","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc-smp","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-powerpc","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-sparc64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-generic-pae","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-virtual","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-server","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-ia64","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-preempt","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-25-versatile","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"},{"name":"linux-image-2.6.32-309-ec2","version":"2.6.32-309.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-309.18"},{"name":"linux-image-2.6.32-25-generic","version":"2.6.32-25.45","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.32-25.45"}],"karmic":[{"name":"linux-ec2","version":"2.6.31-307.21","description":"Linux kernel for EC2","is_source":true},{"name":"linux","version":"2.6.31-22.67","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.31-22-server","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-ia64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-307-ec2","version":"2.6.31-307.21","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-ec2","version_link":"https://launchpad.net/ubuntu/+source/linux-ec2/2.6.31-307.21"},{"name":"linux-image-2.6.31-22-generic-pae","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-386","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-sparc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-virtual","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-powerpc64-smp","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-generic","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"},{"name":"linux-image-2.6.31-22-lpia","version":"2.6.31-22.67","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.31-22.67"}],"hardy":[{"name":"linux","version":"2.6.24-28.80","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.24-28-powerpc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa32","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-generic","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-itanium","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-openvz","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-virtual","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-rt","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpia","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-hppa64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-mckinley","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-server","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-powerpc-smp","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-386","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-lpiacompat","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-sparc64","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"},{"name":"linux-image-2.6.24-28-xen","version":"2.6.24-28.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-28.80"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.89","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.89","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.89"}],"maverick":[{"name":"linux","version":"2.6.35-22.35","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.35-22-generic-pae","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc64-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-versatile","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-generic","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-powerpc-smp","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-virtual","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-server","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"},{"name":"linux-image-2.6.35-22-omap","version":"2.6.35-22.35","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.35-22.35"}],"jaunty":[{"name":"linux","version":"2.6.28-19.66","description":"Linux kernel","is_source":true},{"name":"linux-image-2.6.28-19-lpia","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-versatile","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-imx51","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-generic","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-server","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-ixp4xx","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-virtual","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"},{"name":"linux-image-2.6.28-19-iop32x","version":"2.6.28-19.66","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-19.66"}]},"type":"USN","cves_ids":["CVE-2010-2525","CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2798","CVE-2010-2942","CVE-2010-2946","CVE-2010-2954","CVE-2010-2960","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3080","CVE-2010-3084","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3477","CVE-2010-3705","CVE-2010-3904"]},{"id":"USN-1074-2","title":"Linux kernel vulnerabilities","summary":"Multiple kernel flaws.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":["CVE-2010-NNN2"],"published":"2011-02-28T19:53:03.364606","description":"\nDan Rosenberg discovered that the RDS network protocol did not correctly\ncheck certain parameters. A local attacker could exploit this gain root\nprivileges. (CVE-2010-3904)\n\nNelson Elhage discovered several problems with the Acorn Econet protocol\ndriver. A local user could cause a denial of service via a NULL pointer\ndereference, escalate privileges by overflowing the kernel stack, and\nassign Econet addresses to arbitrary interfaces. (CVE-2010-3848,\nCVE-2010-3849, CVE-2010-3850)\n\nBen Hawkes discovered that the Linux kernel did not correctly filter\nregisters on 64bit kernels when performing 32bit system calls. On a 64bit\nsystem, a local attacker could manipulate 32bit system calls to gain root\nprivileges. (CVE-2010-3301)\n\nBen Hawkes discovered that the Linux kernel did not correctly validate\nmemory ranges on 64bit kernels when allocating memory on behalf of 32bit\nsystem calls. On a 64bit system, a local attacker could perform malicious\nmulticast getsockopt calls to gain root privileges. (CVE-2010-3081)\n\nAl Viro discovered a race condition in the TTY driver. A local attacker\ncould exploit this to crash the system, leading to a denial of service.\n(CVE-2009-4895)\n\nDan Rosenberg discovered that the MOVE_EXT ext4 ioctl did not correctly\ncheck file permissions. A local attacker could overwrite append-only files,\nleading to potential data loss. (CVE-2010-2066)\n\nDan Rosenberg discovered that the swapexit xfs ioctl did not correctly\ncheck file permissions. A local attacker could exploit this to read from\nwrite-only files, leading to a loss of privacy. (CVE-2010-2226)\n\nSuresh Jayaraman discovered that CIFS did not correctly validate certain\nresponse packats. A remote attacker could send specially crafted traffic\nthat would crash the system, leading to a denial of service.\n(CVE-2010-2248)\n\nBen Hutchings discovered that the ethtool interface did not correctly check\ncertain sizes. A local attacker could perform malicious ioctl calls that\ncould crash the system, leading to a denial of service. (CVE-2010-2478,\nCVE-2010-3084)\n\nJames Chapman discovered that L2TP did not correctly evaluate checksum\ncapabilities. If an attacker could make malicious routing changes, they\ncould crash the system, leading to a denial of service. (CVE-2010-2495)\n\nNeil Brown discovered that NFSv4 did not correctly check certain write\nrequests. A remote attacker could send specially crafted traffic that could\ncrash the system or possibly gain root privileges. (CVE-2010-2521)\n\nDavid Howells discovered that DNS resolution in CIFS could be spoofed. A\nlocal attacker could exploit this to control DNS replies, leading to a loss\nof privacy and possible privilege escalation. (CVE-2010-2524)\n\nDan Rosenberg discovered that the btrfs filesystem did not correctly\nvalidate permissions when using the clone function. A local attacker could\noverwrite the contents of file handles that were opened for append-only, or\npotentially read arbitrary contents, leading to a loss of privacy.\n(CVE-2010-2538)\n\nBob Peterson discovered that GFS2 rename operations did not correctly\nvalidate certain sizes. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-2798)\n\nEric Dumazet discovered that many network functions could leak kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-2942, CVE-2010-3477)\n\nDave Chinner discovered that the XFS filesystem did not correctly order\ninode lookups when exported by NFS. A remote attacker could exploit this to\nread or write disk blocks that had changed file assignment or had become\nunlinked, leading to a loss of privacy. (CVE-2010-2943)\n\nSergey Vlasov discovered that JFS did not correctly handle certain extended\nattributes. A local attacker could bypass namespace access rules, leading\nto a loss of privacy. (CVE-2010-2946)\n\nTavis Ormandy discovered that the IRDA subsystem did not correctly shut\ndown. A local attacker could exploit this to cause the system to crash or\npossibly gain root privileges. (CVE-2010-2954)\n\nBrad Spengler discovered that the wireless extensions did not correctly\nvalidate certain request sizes. A local attacker could exploit this to read\nportions of kernel memory, leading to a loss of privacy. (CVE-2010-2955)\n\nKees Cook discovered that the Intel i915 graphics driver did not correctly\nvalidate memory regions. A local attacker with access to the video card\ncould read and write arbitrary kernel memory to gain root privileges.\n(CVE-2010-2962)\n\nKees Cook discovered that the V4L1 32bit compat interface did not correctly\nvalidate certain parameters. A local attacker on a 64bit system with access\nto a video device could exploit this to gain root privileges.\n(CVE-2010-2963)\n\nToshiyuki Okajima discovered that ext4 did not correctly check certain\nparameters. A local attacker could exploit this to crash the system or\noverwrite the last block of large files. (CVE-2010-3015)\n\nTavis Ormandy discovered that the AIO subsystem did not correctly validate\ncertain parameters. A local attacker could exploit this to crash the system\nor possibly gain root privileges. (CVE-2010-3067)\n\nDan Rosenberg discovered that certain XFS ioctls leaked kernel stack\ncontents. A local attacker could exploit this to read portions of kernel\nmemory, leading to a loss of privacy. (CVE-2010-3078)\n\nRobert Swiecki discovered that ftrace did not correctly handle mutexes. A\nlocal attacker could exploit this to crash the kernel, leading to a denial\nof service. (CVE-2010-3079)\n\nTavis Ormandy discovered that the OSS sequencer device did not correctly\nshut down. A local attacker could exploit this to crash the system or\npossibly gain root privileges. (CVE-2010-3080)\n\nDan Rosenberg discovered that several network ioctls did not clear kernel\nmemory correctly. A local user could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-3296, CVE-2010-3297,\nCVE-2010-3298)\n\nDan Rosenberg discovered that the ROSE driver did not correctly check\nparameters. A local attacker with access to a ROSE network device could\nexploit this to crash the system or possibly gain root privileges.\n(CVE-2010-3310)\n\nThomas Dreibholz discovered that SCTP did not correctly handle appending\npacket chunks. A remote attacker could send specially crafted traffic to\ncrash the system, leading to a denial of service. (CVE-2010-3432)\n\nDan Rosenberg discovered that the CD driver did not correctly check\nparameters. A local attacker could exploit this to read arbitrary kernel\nmemory, leading to a loss of privacy. (CVE-2010-3437)\n\nDan Rosenberg discovered that the Sound subsystem did not correctly\nvalidate parameters. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3442)\n\nDan Jacobson discovered that ThinkPad video output was not correctly access\ncontrolled. A local attacker could exploit this to hang the system, leading\nto a denial of service. (CVE-2010-3448)\n\nIt was discovered that KVM did not correctly initialize certain CPU\nregisters. A local attacker could exploit this to crash the system, leading\nto a denial of service. (CVE-2010-3698)\n\nDan Rosenberg discovered that SCTP did not correctly handle HMAC\ncalculations. A remote attacker could send specially crafted traffic that\nwould crash the system, leading to a denial of service. (CVE-2010-3705)\n\nBrad Spengler discovered that stack memory for new a process was not\ncorrectly calculated. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-3858)\n\nKees Cook discovered that the ethtool interface did not correctly clear\nkernel memory. A local attacker could read kernel heap memory, leading to a\nloss of privacy. (CVE-2010-3861)\n\nKees Cook and Vasiliy Kulikov discovered that the shm interface did not\nclear kernel memory correctly. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4072)\n\nDan Rosenberg discovered that IPC structures were not correctly initialized\non 64bit systems. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4073)\n\nDan Rosenberg discovered that the USB subsystem did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4074)\n\nDan Rosenberg discovered that the SiS video driver did not correctly clear\nkernel memory. A local attacker could exploit this to read kernel stack\nmemory, leading to a loss of privacy. (CVE-2010-4078)\n\nDan Rosenberg discovered that the ivtv V4L driver did not correctly\ninitialize certian structures. A local attacker could exploit this to read\nkernel stack memory, leading to a loss of privacy. (CVE-2010-4079)\n\nSteve Chen discovered that setsockopt did not correctly check MSS values. A\nlocal attacker could make a specially crafted socket call to crash the\nsystem, leading to a denial of service. (CVE-2010-4165)\n\nDave Jones discovered that the mprotect system call did not correctly\nhandle merged VMAs. A local attacker could exploit this to crash the\nsystem, leading to a denial of service. (CVE-2010-4169)\n\nVegard Nossum discovered that memory garbage collection was not handled\ncorrectly for active sockets. A local attacker could exploit this to\nallocate all available kernel memory, leading to a denial of service.\n(CVE-2010-4249)\n\nJoel Becker discovered that OCFS2 did not correctly validate on-disk\nsymlink structures. If an attacker were able to trick a user or automated\nsystem into mounting a specially crafted filesystem, it could crash the\nsystem or expose kernel memory, leading to a loss of privacy.\n(CVE-2010-NNN2)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"linux-fsl-imx51","version":"2.6.31-608.22","description":"Linux kernel for FSL IMX51","is_source":true},{"name":"linux-image-2.6.31-608-imx51","version":"2.6.31-608.22","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51","version_link":"https://launchpad.net/ubuntu/+source/linux-fsl-imx51/2.6.31-608.22"}]},"type":"USN","cves_ids":["CVE-2009-4895","CVE-2010-2066","CVE-2010-2226","CVE-2010-2248","CVE-2010-2478","CVE-2010-2495","CVE-2010-2521","CVE-2010-2524","CVE-2010-2538","CVE-2010-2798","CVE-2010-2942","CVE-2010-2943","CVE-2010-2946","CVE-2010-2954","CVE-2010-2955","CVE-2010-2962","CVE-2010-2963","CVE-2010-3015","CVE-2010-3067","CVE-2010-3078","CVE-2010-3079","CVE-2010-3080","CVE-2010-3081","CVE-2010-3084","CVE-2010-3296","CVE-2010-3297","CVE-2010-3298","CVE-2010-3301","CVE-2010-3310","CVE-2010-3432","CVE-2010-3437","CVE-2010-3442","CVE-2010-3448","CVE-2010-3477","CVE-2010-3698","CVE-2010-3705","CVE-2010-3848","CVE-2010-3849","CVE-2010-3850","CVE-2010-3858","CVE-2010-3861","CVE-2010-3904","CVE-2010-4072","CVE-2010-4073","CVE-2010-4074","CVE-2010-4078","CVE-2010-4079","CVE-2010-4165","CVE-2010-4169","CVE-2010-4249"]}]},{"id":"CVE-2010-2956","published":"2010-08-31T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nSudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not\nproperly handle use of the -u option in conjunction with the -g option,\nwhich allows local users to gain privileges via a command line containing a\n\"-u root\" sequence.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"root escalation, but requires non-standard sudoers setup\nsudo 1.6 is not affected (does not have '-g' option)"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.sudo.ws/sudo/alerts/runas_group.html","https://ubuntu.com/security/notices/USN-983-1","https://www.cve.org/CVERecord?id=CVE-2010-2956"],"bugs":[""],"patches":{"sudo":[]},"tags":{},"packages":[{"name":"sudo","source":"https://ubuntu.com/security/cve?package=sudo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sudo","debian":"https://tracker.debian.org/pkg/sudo","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1.7.0-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1.7.2p1-1ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"1.7.4p4","component":null,"pocket":"security"}]}],"notices_ids":["USN-983-1"],"notices":[{"id":"USN-983-1","title":"Sudo vulnerability","summary":"Under non-default configurations, a local user could run programs with\nadministrator privileges.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2010-09-07T13:40:36.491599","description":"Markus Wuethrich discovered that sudo did not always verify the user when a\ngroup was specified in the Runas_Spec. A local attacker could exploit this\nto execute arbitrary code as root if sudo was configured to allow the\nattacker to use a program as a group when the attacker was not a part of\nthat group.\n","is_hidden":false,"release_packages":{"lucid":[{"name":"sudo","version":"1.7.2p1-1ubuntu5.2","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.7.2p1-1ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.2p1-1ubuntu5.2"},{"name":"sudo","version":"1.7.2p1-1ubuntu5.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.2p1-1ubuntu5.2"}],"karmic":[{"name":"sudo","version":"1.7.0-1ubuntu2.5","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo-ldap","version":"1.7.0-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.0-1ubuntu2.5"},{"name":"sudo","version":"1.7.0-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.7.0-1ubuntu2.5"}]},"type":"USN","cves_ids":["CVE-2010-2956"]}]},{"id":"CVE-2010-2575","published":"2010-08-30T21:00:00","updated_at":"2025-05-26T12:47:16.785941+00:00","description":"\nHeap-based buffer overflow in the RLE decompression functionality in the\nTranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp\nin Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a\ndenial of service (application crash) or possibly execute arbitrary code\nvia a crafted image in a PDB file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"patch/cve notification from jriddell\nkpdf (the precursor to okular) does not appear to be\naffected"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2575","https://ubuntu.com/security/notices/USN-979-1"],"bugs":[""],"patches":{"kdegraphics":["upstream: http://websvn.kde.org/?view=revision&revision=1167827"]},"tags":{},"packages":[{"name":"kdegraphics","source":"https://ubuntu.com/security/cve?package=kdegraphics","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kdegraphics","debian":"https://tracker.debian.org/pkg/kdegraphics","statuses":[{"release_codename":"dapper","status":"not-affected","description":"kpdf","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"kpdf","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"4:4.2.2-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"4:4.3.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"4:4.4.2-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-979-1"],"notices":[{"id":"USN-979-1","title":"okular vulnerability","summary":"A heap-based buffer overflow in okular.\n","instructions":"After a standard system update you need to restart any running instances\nof okular to make all the necessary changes.\n","references":[],"published":"2010-08-27T01:06:17.011329","description":"Stefan Cornelius of Secunia Research discovered a boundary error during\nRLE decompression in the \"TranscribePalmImageToJPEG()\" function in\ngenerators/plucker/inplug/image.cpp of okular when processing images\nembedded in PDB files, which can be exploited to cause a heap-based\nbuffer overflow. (CVE-2010-2575)\n","is_hidden":false,"release_packages":{"lucid":[{"name":"kdegraphics","version":"4:4.4.2-0ubuntu1.1","description":"graphics applications from the official KDE 4 release","is_source":true},{"name":"okular","version":"4:4.4.2-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdegraphics","version_link":"https://launchpad.net/ubuntu/+source/kdegraphics/4:4.4.2-0ubuntu1.1"}],"jaunty":[{"name":"kdegraphics","version":"4:4.2.2-0ubuntu2.1","description":"graphics applications from the official KDE 4 release","is_source":true},{"name":"okular","version":"4:4.2.2-0ubuntu2.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdegraphics","version_link":"https://launchpad.net/ubuntu/+source/kdegraphics/4:4.2.2-0ubuntu2.1"}],"karmic":[{"name":"kdegraphics","version":"4:4.3.2-0ubuntu1.1","description":"graphics applications from the official KDE 4 release","is_source":true},{"name":"okular","version":"4:4.3.2-0ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/kdegraphics","version_link":"https://launchpad.net/ubuntu/+source/kdegraphics/4:4.3.2-0ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2010-2575"]}]},{"id":"CVE-2010-2945","published":"2010-08-30T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe default configuration of SLiM before 1.3.2 places ./ (dot slash) at the\nbeginning of the default_path option, which might allow local users to gain\nprivileges via a Trojan horse program in the current working directory,\nrelated to slim.conf and cfg.cpp.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2945"],"bugs":[""],"patches":{"slim":[]},"tags":{},"packages":[{"name":"slim","source":"https://ubuntu.com/security/cve?package=slim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=slim","debian":"https://tracker.debian.org/pkg/slim","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.3.1-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.1-7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-2940","published":"2010-08-30T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe auth_send function in providers/ldap/ldap_auth.c in System Security\nServices Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind\nare enabled, allows remote attackers to bypass the authentication\nrequirements of pam_authenticate via an empty password.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-2940"],"bugs":[""],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"1.2.1-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.1-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3133","published":"2010-08-26T18:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and\n1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to\nexecute arbitrary code and conduct DLL hijacking attacks via a Trojan horse\nairpcap.dll, and possibly other DLLs, that is located in the same folder as\na file that automatically launches Wireshark.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Windows only"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.wireshark.org/security/wnpa-sec-2010-10.html","https://www.cve.org/CVERecord?id=CVE-2010-3133"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3124","published":"2010-08-26T18:36:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUntrusted search path vulnerability in bin/winvlc.c in VLC Media Player\n1.1.3 and earlier allows local users, and possibly remote attackers, to\nexecute arbitrary code and conduct DLL hijacking attacks via a Trojan horse\nwintab32.dll that is located in the same folder as a .mp3 file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is Windows-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3124"],"bugs":[""],"patches":{"vlc":["upstream: http://git.videolan.org/?p=vlc/vlc-1.1.git;a=blobdiff;f=bin/winvlc.c;h=ac9b97ca9f5f9ba001f13bf61eb5127a1c1dbcbf;hp=2d09cba320e3b0def7069ce1ebab25d1340161c5;hb=43a31df56c37bd62c691cdbe3c1f11babd164b56;hpb=2d366da738b19f8d761d7084746c6db6f52808c6"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.1.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3743","published":"2010-08-26T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOff-by-one error in the Ins_MINDEX function in the TrueType bytecode\ninterpreter in Ghostscript before 8.71 allows remote attackers to execute\narbitrary code or cause a denial of service (heap memory corruption) via a\nmalformed TrueType font in a document that trigger an integer overflow and\na heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1317-1","https://www.cve.org/CVERecord?id=CVE-2009-3743"],"bugs":["http://bugs.ghostscript.com/show_bug.cgi?id=691044"],"patches":{"ghostscript":["upstream: http://ghostscript.com/pipermail/gs-cvs/2010-January/010345.html"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"8.61.dfsg.1-1ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-afpl","source":"https://ubuntu.com/security/cve?package=gs-afpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-afpl","debian":"https://tracker.debian.org/pkg/gs-afpl","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-esp","source":"https://ubuntu.com/security/cve?package=gs-esp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-esp","debian":"https://tracker.debian.org/pkg/gs-esp","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gs-gpl","source":"https://ubuntu.com/security/cve?package=gs-gpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gs-gpl","debian":"https://tracker.debian.org/pkg/gs-gpl","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1317-1"],"notices":[{"id":"USN-1317-1","title":"Ghostscript vulnerabilities","summary":"Ghostscript could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2012-01-04T14:29:33.662972","description":"It was discovered that Ghostscript did not correctly handle memory\nallocation when parsing certain malformed JPEG-2000 images. If a user or\nautomated system were tricked into opening a specially crafted image, an\nattacker could cause a denial of service and possibly execute arbitrary\ncode with user privileges. (CVE-2008-3520)\n\nIt was discovered that Ghostscript did not correctly handle certain\nformatting operations when parsing JPEG-2000 images. If a user or automated\nsystem were tricked into opening a specially crafted image, an attacker\ncould cause a denial of service and possibly execute arbitrary code with\nuser privileges. (CVE-2008-3522)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nTrueType fonts. If a user or automated system were tricked into opening a\ndocument containing a specially crafted font, an attacker could cause a\ndenial of service and possibly execute arbitrary code with user privileges.\nThis issue only affected Ubuntu 8.04 LTS. (CVE-2009-3743)\n\nIt was discovered that Ghostscript incorrectly handled certain malformed\nType 2 fonts. If a user or automated system were tricked into opening a\ndocument containing a specially crafted font, an attacker could cause a\ndenial of service and possibly execute arbitrary code with user privileges.\nThis issue only affected Ubuntu 8.04 LTS. (CVE-2010-4054)\n\nJonathan Foote discovered that Ghostscript incorrectly handled certain\nmalformed JPEG-2000 image files. If a user or automated system were tricked\ninto opening a specially crafted JPEG-2000 image file, an attacker could\ncause Ghostscript to crash or possibly execute arbitrary code with user\nprivileges. (CVE-2011-4516, CVE-2011-4517)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"ghostscript","version":"8.61.dfsg.1-1ubuntu3.4","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.61.dfsg.1-1ubuntu3.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.61.dfsg.1-1ubuntu3.4"}],"lucid":[{"name":"ghostscript","version":"8.71.dfsg.1-0ubuntu5.4","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.71.dfsg.1-0ubuntu5.4","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.1-0ubuntu5.4"}],"maverick":[{"name":"ghostscript","version":"8.71.dfsg.2-0ubuntu7.1","description":"The GPL Ghostscript PostScript/PDF interpreter","is_source":true},{"name":"libgs8","version":"8.71.dfsg.2-0ubuntu7.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/8.71.dfsg.2-0ubuntu7.1"}]},"type":"USN","cves_ids":["CVE-2008-3520","CVE-2008-3522","CVE-2009-3743","CVE-2010-4054","CVE-2011-4516","CVE-2011-4517"]}]},{"id":"CVE-2010-2936","published":"2010-08-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInteger overflow in simpress.bin in the Impress module in OpenOffice.org\n(OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of\nservice (application crash) or possibly execute arbitrary code via crafted\npolygons in a PowerPoint document that triggers a heap-based buffer\noverflow.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"protected by heap-protector, downgrading to low"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1056-1","https://www.cve.org/CVERecord?id=CVE-2010-2936"],"bugs":[""],"patches":{"openoffice.org":[],"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3","component":null,"pocket":"security"}]},{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:2.4.1-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:3.1.1-5ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1:3.2.0-7ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1:3.2.1-7ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.2.1-6","component":null,"pocket":"security"}]}],"notices_ids":["USN-1056-1"],"notices":[{"id":"USN-1056-1","title":"OpenOffice.org vulnerabilities","summary":"Multiple vulnerabilities in OpenOffice.org\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-02-02T22:31:33.585471","description":"Charlie Miller discovered several heap overflows in PPT processing. If\na user or automated system were tricked into opening a specially crafted\nPPT document, a remote attacker could execute arbitrary code with user\nprivileges. Ubuntu 10.10 was not affected. (CVE-2010-2935, CVE-2010-2936)\n\nMarc Schoenefeld discovered that directory traversal was not correctly\nhandled in XSLT, OXT, JAR, or ZIP files. If a user or automated system\nwere tricked into opening a specially crafted document, a remote attacker\noverwrite arbitrary files, possibly leading to arbitrary code execution\nwith user privileges. (CVE-2010-3450)\n\nDan Rosenberg discovered multiple heap overflows in RTF and DOC\nprocessing. If a user or automated system were tricked into opening a\nspecially crafted RTF or DOC document, a remote attacker could execute\narbitrary code with user privileges. (CVE-2010-3451, CVE-2010-3452,\nCVE-2010-3453, CVE-2010-3454)\n\nDmitri Gribenko discovered that OpenOffice.org did not correctly\nhandle LD_LIBRARY_PATH in various tools. If a local attacker\ntricked a user or automated system into using OpenOffice.org from an\nattacker-controlled directory, they could execute arbitrary code with\nuser privileges. (CVE-2010-3689)\n\nMarc Schoenefeld discovered that OpenOffice.org did not correctly process\nPNG images. If a user or automated system were tricked into opening a\nspecially crafted document, a remote attacker could execute arbitrary\ncode with user privileges. (CVE-2010-4253)\n\nIt was discovered that OpenOffice.org did not correctly process TGA\nimages. If a user or automated system were tricked into opening a\nspecially crafted document, a remote attacker could execute arbitrary\ncode with user privileges. (CVE-2010-4643)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openoffice.org","version":"1:2.4.1-1ubuntu2.5","description":"OpenOffice.org Office suite","is_source":true},{"name":"openoffice.org-impress","version":"1:2.4.1-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:2.4.1-1ubuntu2.5"},{"name":"openoffice.org-writer","version":"1:2.4.1-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:2.4.1-1ubuntu2.5"},{"name":"openoffice.org-core","version":"1:2.4.1-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:2.4.1-1ubuntu2.5"}],"lucid":[{"name":"openoffice.org","version":"1:3.2.0-7ubuntu4.2","description":"office productivity suite","is_source":true},{"name":"openoffice.org-impress","version":"1:3.2.0-7ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.0-7ubuntu4.2"},{"name":"openoffice.org-writer","version":"1:3.2.0-7ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.0-7ubuntu4.2"},{"name":"openoffice.org-core","version":"1:3.2.0-7ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.0-7ubuntu4.2"}],"maverick":[{"name":"openoffice.org","version":"1:3.2.1-7ubuntu1.1","description":"office productivity suite","is_source":true},{"name":"openoffice.org-impress","version":"1:3.2.1-7ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.1-7ubuntu1.1"},{"name":"openoffice.org-writer","version":"1:3.2.1-7ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.1-7ubuntu1.1"},{"name":"openoffice.org-core","version":"1:3.2.1-7ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.1-7ubuntu1.1"}],"karmic":[{"name":"openoffice.org","version":"1:3.1.1-5ubuntu1.3","description":"full-featured office productivity suite","is_source":true},{"name":"openoffice.org-impress","version":"1:3.1.1-5ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.1.1-5ubuntu1.3"},{"name":"openoffice.org-writer","version":"1:3.1.1-5ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.1.1-5ubuntu1.3"},{"name":"openoffice.org-core","version":"1:3.1.1-5ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.1.1-5ubuntu1.3"}]},"type":"USN","cves_ids":["CVE-2010-2935","CVE-2010-2936","CVE-2010-3450","CVE-2010-3451","CVE-2010-3452","CVE-2010-3453","CVE-2010-3454","CVE-2010-3689","CVE-2010-4253","CVE-2010-4643"]}]},{"id":"CVE-2010-2935","published":"2010-08-25T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsimpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x\nbefore 3.3 does not properly handle integer values associated with\ndictionary property items, which allows remote attackers to cause a denial\nof service (application crash) or possibly execute arbitrary code via a\ncrafted PowerPoint document that triggers a heap-based buffer overflow,\nrelated to an \"integer truncation error.\"","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"protected by heap-protector, downgrading to low"},{"author":"jdstrand","note":"libreoffice 1:3.3.4-0ubuntu1 are already fixed"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-1056-1","https://www.cve.org/CVERecord?id=CVE-2010-2935"],"bugs":[""],"patches":{"openoffice.org":[],"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1:2.4.1-1ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"1:3.1.1-5ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"1:3.2.0-7ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"maverick","status":"released","description":"1:3.2.1-7ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"transitional package","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"transitional package","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"transitional package","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1056-1"],"notices":[{"id":"USN-1056-1","title":"OpenOffice.org vulnerabilities","summary":"Multiple vulnerabilities in OpenOffice.org\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2011-02-02T22:31:33.585471","description":"Charlie Miller discovered several heap overflows in PPT processing. If\na user or automated system were tricked into opening a specially crafted\nPPT document, a remote attacker could execute arbitrary code with user\nprivileges. Ubuntu 10.10 was not affected. (CVE-2010-2935, CVE-2010-2936)\n\nMarc Schoenefeld discovered that directory traversal was not correctly\nhandled in XSLT, OXT, JAR, or ZIP files. If a user or automated system\nwere tricked into opening a specially crafted document, a remote attacker\noverwrite arbitrary files, possibly leading to arbitrary code execution\nwith user privileges. (CVE-2010-3450)\n\nDan Rosenberg discovered multiple heap overflows in RTF and DOC\nprocessing. If a user or automated system were tricked into opening a\nspecially crafted RTF or DOC document, a remote attacker could execute\narbitrary code with user privileges. (CVE-2010-3451, CVE-2010-3452,\nCVE-2010-3453, CVE-2010-3454)\n\nDmitri Gribenko discovered that OpenOffice.org did not correctly\nhandle LD_LIBRARY_PATH in various tools. If a local attacker\ntricked a user or automated system into using OpenOffice.org from an\nattacker-controlled directory, they could execute arbitrary code with\nuser privileges. (CVE-2010-3689)\n\nMarc Schoenefeld discovered that OpenOffice.org did not correctly process\nPNG images. If a user or automated system were tricked into opening a\nspecially crafted document, a remote attacker could execute arbitrary\ncode with user privileges. (CVE-2010-4253)\n\nIt was discovered that OpenOffice.org did not correctly process TGA\nimages. If a user or automated system were tricked into opening a\nspecially crafted document, a remote attacker could execute arbitrary\ncode with user privileges. (CVE-2010-4643)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"openoffice.org","version":"1:2.4.1-1ubuntu2.5","description":"OpenOffice.org Office suite","is_source":true},{"name":"openoffice.org-impress","version":"1:2.4.1-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:2.4.1-1ubuntu2.5"},{"name":"openoffice.org-writer","version":"1:2.4.1-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:2.4.1-1ubuntu2.5"},{"name":"openoffice.org-core","version":"1:2.4.1-1ubuntu2.5","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:2.4.1-1ubuntu2.5"}],"lucid":[{"name":"openoffice.org","version":"1:3.2.0-7ubuntu4.2","description":"office productivity suite","is_source":true},{"name":"openoffice.org-impress","version":"1:3.2.0-7ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.0-7ubuntu4.2"},{"name":"openoffice.org-writer","version":"1:3.2.0-7ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.0-7ubuntu4.2"},{"name":"openoffice.org-core","version":"1:3.2.0-7ubuntu4.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.0-7ubuntu4.2"}],"maverick":[{"name":"openoffice.org","version":"1:3.2.1-7ubuntu1.1","description":"office productivity suite","is_source":true},{"name":"openoffice.org-impress","version":"1:3.2.1-7ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.1-7ubuntu1.1"},{"name":"openoffice.org-writer","version":"1:3.2.1-7ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.1-7ubuntu1.1"},{"name":"openoffice.org-core","version":"1:3.2.1-7ubuntu1.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.2.1-7ubuntu1.1"}],"karmic":[{"name":"openoffice.org","version":"1:3.1.1-5ubuntu1.3","description":"full-featured office productivity suite","is_source":true},{"name":"openoffice.org-impress","version":"1:3.1.1-5ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.1.1-5ubuntu1.3"},{"name":"openoffice.org-writer","version":"1:3.1.1-5ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.1.1-5ubuntu1.3"},{"name":"openoffice.org-core","version":"1:3.1.1-5ubuntu1.3","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openoffice.org","version_link":"https://launchpad.net/ubuntu/+source/openoffice.org/1:3.1.1-5ubuntu1.3"}]},"type":"USN","cves_ids":["CVE-2010-2935","CVE-2010-2936","CVE-2010-3450","CVE-2010-3451","CVE-2010-3452","CVE-2010-3453","CVE-2010-3454","CVE-2010-3689","CVE-2010-4253","CVE-2010-4643"]}]},{"id":"CVE-2010-3119","published":"2010-08-24T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly\nsupport the Ruby language, which allows attackers to cause a denial of\nservice (memory corruption) or possibly have unspecified other impact via\nunknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3119"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=43795"],"patches":{"webkit":["upstream: http://trac.webkit.org/changeset/65090"],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.127","component":null,"pocket":"security"}]},{"name":"webkit","source":"https://ubuntu.com/security/cve?package=webkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit","debian":"https://tracker.debian.org/pkg/webkit","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"karmic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3118","published":"2010-08-24T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe autosuggest feature in the Omnibox implementation in Google Chrome\nbefore 5.0.375.127 does not anticipate entry of passwords, which might\nallow remote attackers to obtain sensitive information by reading the\nnetwork traffic generated by this feature.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chromium-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3118"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.127","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2010-3117","published":"2010-08-24T20:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGoogle Chrome before 5.0.375.127 does not properly implement the\nnotifications feature, which allows remote attackers to cause a denial of\nservice (application crash) and possibly have unspecified other impact via\nunknown vectors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"chromium-specific"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2010-3117"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6.0.472.53~r57914-0ubuntu0.10.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.375.127","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":72420,"limit":20,"total_results":79316}