Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: dann frazier <dannf <at> debian.org>
Subject: [DSA 2632-1] linux-2.6 security update
Newsgroups: gmane.linux.debian.user.security.announce
Date: Tuesday 26th February 2013 03:58:48 UTC (over 3 years ago)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ----------------------------------------------------------------------
Debian Security Advisory DSA-2632-1                [email protected]
http://www.debian.org/security/ 
                         Dann Frazier
February 25, 2013                   http://www.debian.org/security/faq
- ----------------------------------------------------------------------

Package        : linux-2.6
Vulnerability  : privilege escalation/denial of service
Problem type   : local
Debian-specific: no
CVE Id(s)      : CVE-2013-0231 CVE-2013-0871

Several vulnerabilities have been discovered in the Linux kernel that may
lead
to a denial of service or privilege escalation. The Common Vulnerabilities
and
Exposures project identifies the following problems:

CVE-2013-0231

    Jan Beulich provided a fix for an issue in the Xen PCI backend drivers.
    Users of guests on a system using passed-through PCI devices can create
    a denial of service of the host system due to the use of
non-ratelimited
    kernel log messages.

CVE-2013-0871

    Suleiman Souhlal and Salman Qazi of Google, with help from Aaron Durbin
    and Michael Davidson of Google, discovered an issue in the
    ptrace subsystem. Due to a race condition with PTRACE_SETREGS, local
users
    can cause kernel stack corruption and execution of arbitrary code.

For the stable distribution (squeeze), this problem has been fixed in
version
2.6.32-48squeeze1.

The following matrix lists additional source packages that were rebuilt for
compatibility with or to take advantage of this update:

                                             Debian 6.0 (squeeze)
     user-mode-linux                         2.6.32-1um-4+48squeeze1

We recommend that you upgrade your linux-2.6 and user-mode-linux packages.

Thanks to Micah Anderson for proof reading this text.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBAgAGBQJRLBVjAAoJEBv4PF5U/IZAu4kP/jZv5pYzgQxM89D3a2GKaaSk
qZV9IHYItKaX2rWURo0vjilp0WZVASCgPX9YB3J+oTxZeMboeRVVllLIwW2L+V0B
zGeQeCZM6YJmc32sGRX+8JNjdeLioDK0vTSzwhUVVJHgO7mYCuWxn8nv2edyyYYL
M0qjAuwZQMuGuDeF8vH5Ef2wNibZeMavqq33OQWr7Yi32hNJdgSzojwQ4lSv81U1
YR+lMJFLnPL9BMUY4kNrGJ4eYxr5rpI4FKEItp0zPsOaskU7zIiV0oWOthUM7sk3
ljagXj/3w/a6dUqH3anAYEB7gU1wwQmHwtbQTnBGnFVgTY+P26FVWq3XEy80Fb0u
K2f5OHi6ChGFXRZmprhjRq/LxlkFLWO/YUtEFpudu2qTesSq9FXRQzfRWD1FLTxS
+t6RbyAEKpCdakVGjIM7zzEo6XzVC5iZBWa15c8rthuJmJtC9zvwEQTx4pVnxwNo
aCqih+BbmJCZWPjDV4Csw61oRh9bDHZrvGqyw1aPrZmefeJ0VvGiwRE9Hf607Aby
2fenrRULteAvZfASZx7IuFaoXT90MKRJMb+Ha2pUyG5dt6t1xU2IQf/NZ+ib/8nl
R1LxICNeHbSkcesbtWVfs11zE88FYikK/h2ZbCtF6jalUSQvIpLFDmYpKRlChUQA
4WsJP7RDW9NNCcsAwuxG
=7Aaz
-----END PGP SIGNATURE-----
 
CD: 3ms