你好,游客! 登陆 或 注册 | 无图版 | 首 页 | 教育论坛 | 同城博客 | 搜 索 | 帮 助
  • 首 页
  • 隆安茶馆
  • 文学天地
  • 休闲娱乐
  • 校园写真
  • 教师之家
  • 电脑乐园
  • 教育动态

 

  隆安教育博客 » 电脑乐园 » 软硬兼施 » Ubuntu发现影响所有版本内核安全漏洞

0
Ubuntu发现影响所有版本内核安全漏洞
 
作者: 陆运文 发表日期: 2008-11-30 复制链接 收藏

  11月27日,Ubuntu开发者为6.06 LTS, 7.10, 8.04 LTS以及8.10这几个版本发布了重要安全更新,补丁修复了9个内核安全安全问题,因此强烈建议Ubuntu用户尽快升级自己的系统。
  
  内核安全漏洞列表

  1. The Xen hypervisor block driver couldn't accurately validate incoming requests. Therefore, a user with root privileges could crash a system and cause a DoS (Denial of Service) attack by executing malicious I/O requests. This issue affects only Ubuntu 7.10.
  
  2. The i915 video driver couldn't accurately validate memory addresses. Therefore, an attacker could remap memory and cause a system crash, leading to a DoS (Denial of Service) attack. Ubuntu 6.06 LTS, 7.10 and 8.04 LTS users are not affected by this issue. Ubuntu 8.10 users should update their systems to correct this vulnerability!
  
  3. When files were created in the setgid directories, the Linux kernel package couldn't accurately strip permissions. Because of this, a local user could gain extra group privileges. This issue was discovered by David Watson and it affects only Ubuntu 6.06 LTS users!
  
  4. When file splice requests were handled, the Linux kernel package couldn't accurately reject the ”append“ flag. Therefore, a local attacker could create changes to random locations in a file by bypassing the append mode. This issue was discovered by Olaf Kirch and Miklos Szeredi, and affects only Ubuntu 7.10 and 8.04 LTS users!
  
  5. The SCTP stack couldn't accurately handle INIT-ACK. Because of this, a remote user could send specially crafted SCTP traffic and crash the system, leading to a DoS (Denial of Service) attack. This issue affects only Ubuntu 8.10 users!
  
  6. The SCTP stack couldn't accurately handle the length of bad packets. Because of this, a remote user could send specially crafted SCTP traffic and crash the system, leading to a DoS (Denial of Service) attack. This issue affects only Ubuntu 8.10 users!
  
  7. The HFS+ filesystem had several flaws. Because of this, a user could be tricked to mount a malicious HFS+ filesystem, which could lead to a DoS (Denial of Service) attack and crash the system. This issue was discovered by Eric Sesterhenn, and affects all Ubuntu users!
  
  8. The Unix Socket handler couldn't accurately process the SCM_RIGHTS message. Therefore, a local attacker could create a malicious socket request and crash the system, leading to a DoS (Denial of Service) attack. This issue affects all Ubuntu users!
  
  9. The i2c audio driver couldn't accurately validate several function pointers. Therefore, a local users could obtain root privileges and crash the system, leading to a DoS (Denial of Service) attack. This issue affects all Ubuntu users!
  
  Ubuntu 6.06 LTS 要将内核升级到linux-image-2.6.15-53.74
  
  Ubuntu 7.10 要将内核升级到  linux-image-2.6.22-16.60
  
  Ubuntu 8.04 LTS 要将内核升级到 LTS linux-image-2.6.24-22.45
  
  Ubuntu 8.10 要将内核升级到 linux-image-2.6.27-9.19

 
欢迎到 陆运文 的个人主页看更多内容阅读全文 (0) | 回复 0 | 推送
搜索

系统公告

  • 从今天起关闭博客中的朋友圈!
  • 隆安教育博客规则

  • 免费赠送二级域名(中英文均可)

小调查

你是怎么知道这个网站的?
  • 1、通过搜索网站找到
  • 2、通过其他网站的链接找到
  • 3、朋友推荐
  • 4、误闯进来

新加入

  • 小雨莹莹
  • 凌凌七
  • 打破记录
  • 名剪
  • beゐlieve
  • 太阳东升了
  • haoqiao333

朋友圈分类

  • » 影视音乐
  • » 星座情缘
  • » 体育联盟
  • » 职业交流
  • » 技术联盟
  • » 同城对碰
  • » 生活休闲
  • » 原创空间
[ 隆安教育信息网 - 隆安教育论坛 - 隆安教育博客 - 广西隆安县教育局版权所有 ]
地址:广西南宁市隆安县城厢镇城内街79号 邮编:532700 电话:0771-6522141 传真:0771-6526903
Powered by PWBlog v5.1.5 Code © 2003-06 桂ICP备05000698号 建议使用1024×768分辨率IE6.0以上浏览器
网站测速 XML Time 0.009700 second(s),query:4 Gzip enabled,Built in Aug,2004.