男人就应该对自己狠一点... 注册 | 登陆

Ubuntu内核安全漏洞

11月27日,Ubuntu开发者为6.06 LTS, 7.10, 8.04 LTS以及8.10这几个版本发布了重要安全更新,补丁修复了9个内核安全安全问题,因此强烈建议Ubuntu用户尽快升级自己的系统,之前文章介绍过 从Linux硬盘安装Ubuntu 8.10  以及揭密秘笈:用Ubuntu破解WEP密钥


Ubuntu内核安全漏洞

1. The Xen hypervisor block driver couldn't accurately validate incoming requests. Therefore, a user with root privileges could crash a system and cause a DoS (Denial of Service) attack by executing malicious I/O requests. This issue affects only Ubuntu 7.10.
 
2. The i915 video driver couldn't accurately validate memory addresses. Therefore, an attacker could remap memory and cause a system crash, leading to a DoS (Denial of Service) attack. Ubuntu 6.06 LTS, 7.10 and 8.04 LTS users are not affected by this issue. Ubuntu 8.10 users should update their systems to correct this vulnerability!
 
3. When files were created in the setgid directories, the Linux kernel package couldn't accurately strip permissions. Because of this, a local user could gain extra group privileges. This issue was discovered by David Watson and it affects only Ubuntu 6.06 LTS users!
 
4. When file splice requests were handled, the Linux kernel package couldn't accurately reject the "append" flag. Therefore, a local attacker could create changes to random locations in a file by bypassing the append mode. This issue was discovered by Olaf Kirch and Miklos Szeredi, and affects only Ubuntu 7.10 and 8.04 LTS users!
 
5. The SCTP stack couldn't accurately handle INIT-ACK. Because of this, a remote user could send specially crafted SCTP traffic and crash the system, leading to a DoS (Denial of Service) attack. This issue affects only Ubuntu 8.10 users!
 
6. The SCTP stack couldn't accurately handle the length of bad packets. Because of this, a remote user could send specially crafted SCTP traffic and crash the system, leading to a DoS (Denial of Service) attack. This issue affects only Ubuntu 8.10 users!
 
7. The HFS+ filesystem had several flaws. Because of this, a user could be tricked to mount a malicious HFS+ filesystem, which could lead to a DoS (Denial of Service) attack and crash the system. This issue was discovered by Eric Sesterhenn, and affects all Ubuntu users!
 
8. The Unix Socket handler couldn't accurately process the SCM_RIGHTS message. Therefore, a local attacker could create a malicious socket request and crash the system, leading to a DoS (Denial of Service) attack. This issue affects all Ubuntu users!
 
9. The i2c audio driver couldn't accurately validate several function pointers. Therefore, a local users could obtain root privileges and crash the system, leading to a DoS (Denial of Service) attack. This issue affects all Ubuntu users!
 
Ubuntu 6.06 LTS 要将内核升级到linux-image-2.6.15-53.74
Ubuntu 7.10 要将内核升级到  linux-image-2.6.22-16.60
Ubuntu 8.04 LTS 要将内核升级到 LTS linux-image-2.6.24-22.45
Ubuntu 8.10 要将内核升级到 linux-image-2.6.27-9.19

Tags: ubuntu, 漏洞, 内核

只显示20条记录相关文章

Linux出错提示信息详解 (浏览: 674, 评论: 0)
Ubuntu下开发环境搭建 C|C++|GTK等 (浏览: 1145, 评论: 0)
IE7漏洞0day及解决方案 (浏览: 750, 评论: 0)
phpMyAdmin 3.1.0 (XSRF)注入漏洞 (浏览: 1046, 评论: 0)
RealPlayer for linux安装使用 ubuntu播放RMVB (浏览: 2529, 评论: 0)
恶搞如果Matrix使用windows系统? (浏览: 942, 评论: 0)
ubuntu下安装MySQL安装指南 (浏览: 1262, 评论: 0)
Ubuntu上建立WordPress环境 (浏览: 1132, 评论: 0)
ubuntu 8.04 3D 桌面设置记录 (浏览: 1155, 评论: 0)
安装ubuntu 8.04 后的一些设置 (浏览: 1074, 评论: 0)
ubuntu(Kubuntu)-中文输入法的安装配置 (浏览: 1482, 评论: 0)
Ubuntu 8.10 (最终版本)发布 (浏览: 1048, 评论: 0)
Linux内核源代码的结构 (浏览: 1384, 评论: 0)
Linux操作系统驱动编译与运行 (浏览: 796, 评论: 0)
Ubuntu 8.10 RC发布 (浏览: 933, 评论: 0)
从Linux内核的漏洞角度考虑系统安全 (浏览: 908, 评论: 0)
下一版本的Ubuntu将给我们带来什么? (浏览: 1152, 评论: 1)
利用MS08-058攻击Google (浏览: 970, 评论: 0)
什么是 Ubuntu? Ubuntu下载|Ubuntup安装 (浏览: 1646, 评论: 0)
研究人员揭露Google Apps安全漏洞 (浏览: 872, 评论: 0)

Trackbacks

点击获得Trackback地址,Encode: UTF-8 老臧's blog

发表评论

评论内容 (必填):