Thursday, September 2, 2010

Linux: kernel regression

Users of Linux please be advised of a kernel regression vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
USN-974-2: [USN-974-2] Linux kernel regression
linux regression
A security issue affects the following Ubuntu releases:



Ubuntu 8.04 LTS



This advisory also applies to the corresponding versions of

Kubuntu, Edubuntu, and Xubuntu.


Original advisory details:



Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory

manager did not properly handle when applications grow stacks into adjacent

memory regions. A local attacker could exploit this to gain control of

certain applications, potentially leading to privilege escalation, as

demonstrated in attacks against the X server. (CVE-2010-2240)


Read more at www.criticalwatch.com
 

No comments:

Post a Comment