18/3/10

Descubiertas vulnerabilidades en el kernel de Ubuntu

se han descubierto una vulnerabilidad en el kernel de una serie de lanzamientos de Ubuntu, que cubre 6.06 LTS a 9.10, incluyendo también las distribuciones Kubuntu, Edubuntu, Xubuntu.

He aquí los hechos, con una frase clave que se destaca:

Mathias Krause discovered that the Linux kernel did not correctly handle missing ELF interpreters. A local attacker could exploit this to cause the system to crash, leading to a denial of service. (CVE-2010-0307)

Marcelo Tosatti discovered that the Linux kernel’s hardware virtualization did not correctly handle reading the /dev/port special device. A local attacker in a guest operating system could issue a specific read that would cause the host system to crash, leading to a denial of service. (CVE-2010-0309)

Sebastian Krahmer discovered that the Linux kernel did not correctly handle netlink connector messages. A local attacker could exploit this to consume kernel memory, leading to a denial of service. (CVE-2010-0410)

Ramon de Carvalho Valle discovered that the Linux kernel did not correctly validate certain memory migration calls. A local attacker could exploit this to read arbitrary kernel memory or cause a system crash, leading to a denial of service. (CVE-2010-0415)

Jermome Marchand and Mikael Pettersson discovered that the Linux kernel did not correctly handle certain futex operations. A local attacker could exploit this to cause a system crash, leading to a denial of service. (CVE-2010-0622, CVE-2010-0623).

Frase clave: "A local attacker"...estos exploits no pueden ser aprovechados de forma remota, es decir, el cielo no está cayendo sobre los usuarios de Linux.

Las actualizaciones están disponibles para distribuciones afectadas.


 

Seguidores

Geeks de GZ

GEEKS ZONE By RHO Copyright © 2009 Gadget Blog is Designed by Ipietoon Sponsored by Online Business Journal