lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20081105095253.GO9448@outflux.net>
Date: Wed, 5 Nov 2008 01:52:53 -0800
From: Kees Cook <kees@...ntu.com>
To: ubuntu-security-announce@...ts.ubuntu.com
Cc: full-disclosure@...ts.grok.org.uk, bugtraq@...urityfocus.com
Subject: [USN-662-1] Linux kernel vulnerabilities

===========================================================
Ubuntu Security Notice USN-662-1          November 05, 2008
linux vulnerability
CVE-2008-3528, CVE-2008-4395
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.10:
  linux-image-2.6.27-7-generic    2.6.27-7.16
  linux-image-2.6.27-7-server     2.6.27-7.16
  linux-image-2.6.27-7-virtual    2.6.27-7.16

After a standard system upgrade you need to reboot your computer to
effect the necessary changes.

Details follow:

It was discovered that the Linux kernel could be made to hang temporarily
when mounting corrupted ext2/3 filesystems.  If a user were tricked into
mounting a specially crafted filesystem, a remote attacker could cause
system hangs, leading to a denial of service. (CVE-2008-3528)

Anders Kaseorg discovered that ndiswrapper did not correctly handle long
ESSIDs.  For a system using ndiswrapper, a physically near-by attacker
could generate specially crafted wireless network traffic and execute
arbitrary code with root privileges. (CVE-2008-4395)


Updated packages for Ubuntu 8.10:

  Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux_2.6.27-7.16.diff.gz
      Size/MD5:  2863888 b1052e6aee92d46c4145620b1b8e65ee
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux_2.6.27-7.16.dsc
      Size/MD5:     1513 28e5b4d99b4ff47bdd31a7c7c125c3d0
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux_2.6.27.orig.tar.gz
      Size/MD5: 63721466 482b04f680ce6676114ccfaaf8f66a55

  Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-doc-2.6.27_2.6.27-7.16_all.deb
      Size/MD5:  3469330 aa00f7f555299257767ee8bf5d2bd08f
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7_2.6.27-7.16_all.deb
      Size/MD5:  5770686 3f4d5517ab70ac57766244843b06bc24
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-source-2.6.27_2.6.27-7.16_all.deb
      Size/MD5: 51951896 db1f17d562bb0c31e5fd2839dd5538a1

  amd64 architecture (Athlon64, Opteron, EM64T Xeon):

    http://security.ubuntu.com/ubuntu/pool/main/l/linux/acpi-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    36502 7aaa51517f74f727cd9b247ad3bdf241
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/block-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   263916 ffd1d0223f84312694b853ddcc3f6f2a
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/crypto-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    53480 736c4c1f8c1b69408dcef471031af2c1
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fat-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    43114 86d52a39e37574f906424b6bcfb9132e
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fb-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    52364 9e6193a120fd97f0f22eda94ca65d49b
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/firewire-core-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    89712 75b58dda7c91a14f102dd513a9884b91
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/floppy-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    38126 107bd036a86295b765b865b592cae856
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-core-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   676982 b162978a3b55d0a7f3682ea28c23e2b2
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-secondary-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   158454 aaf6ae3e6d430f7e06f71b398e2a7433
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/input-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    46404 52491f24cdfee2795758dd28ab1a8583
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/ipv6-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   154016 054373c25e230ae6d2d7de5026c78aa8
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/irda-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   312610 033df8299f5c265367ea295c83165e3b
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/kernel-image-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:  2596386 37ee7ec2a1d488e6f6de8f34176987f4
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-generic_2.6.27-7.16_amd64.deb
      Size/MD5:   639082 ed8f3a70d90f169d172c6e173e0b6b1b
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-server_2.6.27-7.16_amd64.deb
      Size/MD5:   638916 ffae21ca3ebd4400d503913ea9f08a77
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-generic_2.6.27-7.16_amd64.deb
      Size/MD5: 23022032 fd3e4e8ab005389ec0cc615cea22874d
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-server_2.6.27-7.16_amd64.deb
      Size/MD5: 23010520 0b171157949ada26b8ba89d8e67ddc0e
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-virtual_2.6.27-7.16_amd64.deb
      Size/MD5: 10436412 530186b8d1d7dc10e507e6bc452403ab
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-libc-dev_2.6.27-7.16_amd64.deb
      Size/MD5:   653232 f48b15dbf0ba532ccb97e22a7d3b4627
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/md-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   434628 bc318d4de2651e91305548666dead618
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/message-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   186306 c3ca7cc803a73d5aca4e0c80464d8274
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nfs-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   275524 899bdf5de6963962c89b691eb26cd28d
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:  1743146 5d9c0145c50ab7e0c51fbc0cef950834
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   151282 c02d1b6ef56dc28403beadad2bf88309
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-shared-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   194184 66a2c1f8320659b94f6b90f119a9c964
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-usb-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   167964 df927206736f4f2a8a7be1e7f013194f
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/parport-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    36454 e7312f2e6286590c1dbcbe5e7de35eeb
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/pata-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    83384 5d38ea1f3a73bad990ed52f66c7a7a28
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    71938 087964f10e908341f287ccea80e27008
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-storage-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    23244 643c72067e2cb27c1ec228fc8d57e217
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/plip-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:     9012 360892e9ef95ab6bd1dc90bb9e08249d
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/ppp-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    68450 67e964ac3d95c5f4a1b12e6b271de74a
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/sata-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   110228 e18c86fcc58d390c4d2ad0e58fcb16a9
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/scsi-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:  1275798 5242af32c6a8a1e38f31e7d8d8857644
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/serial-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    47570 f8e459e40f399d1f966111122344504b
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/socket-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    13312 03eb83515fc5d90aeb272c540e165c6f
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/storage-core-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   391200 b7c4499c38f44e23908ef0fb63bdca45
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/usb-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:   198786 770b109f3971e9718fbeb2cc5f05c35d
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/virtio-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
      Size/MD5:    13578 dba0b8949f78e43c90545b7fd092c7b6

  i386 architecture (x86 compatible Intel/AMD):

    http://security.ubuntu.com/ubuntu/pool/main/l/linux/acpi-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    33934 cfb49d89dd70429f2b730c7a2e8964b8
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/block-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   244326 f8aedcc6ff1c95f0bacd870628bd34bd
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/crypto-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    55394 ee8205b481dd6112058349957db14aa6
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fat-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    41252 54cf9023f441a0699b3b380de4058160
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fb-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    48696 2e10bdbbd0be743e553bfd937ba44d9a
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/firewire-core-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    86902 f5ed38f167db71b3601d1811a8b45a17
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/floppy-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    33940 2e90360f4470554283ebd7670cad3a57
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-core-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   674272 22f6dcac8dce84d5163d062bdf09460f
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-secondary-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   158080 80298237cf5abe9f179750748d4858f4
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/input-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    43708 d3135a501ea45cf5e18576c92cee7759
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/ipv6-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   144930 abadde5392b98fcdb9d7ce8fa508f746
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/irda-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   301938 1f69318efc172f2bdab1ca436471ea48
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/kernel-image-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:  2427088 0e03f701335f5379361ce51bec448626
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-generic_2.6.27-7.16_i386.deb
      Size/MD5:   620778 7228c2aa323fcf657c4d69263ea1821a
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-server_2.6.27-7.16_i386.deb
      Size/MD5:   622006 75832cee4f8b79b1add067a274885c04
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-generic_2.6.27-7.16_i386.deb
      Size/MD5: 23398356 d5209ae17503b72ba9024f6ae5ba2a05
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-server_2.6.27-7.16_i386.deb
      Size/MD5: 23535584 4af9bab584739538dcb962c208cdd31d
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-virtual_2.6.27-7.16_i386.deb
      Size/MD5: 10068962 55196eb464330b1376db54f0a93b9a04
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-libc-dev_2.6.27-7.16_i386.deb
      Size/MD5:   653202 18623f809fe95a1fce18d03b727d2f72
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/md-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   432650 7102e7cd30bddcc5c64c9949a3b00fc9
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/message-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   170996 d1b2396fefe97dd11b56d0ab9b6bc8ef
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nfs-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   263918 70f6f3a4c7d11b3dc83e0ea3892a3b4c
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:  1929778 484509b351a85edca959c0308251633e
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   150870 2ffdb3d3586d260c172a4c2a10704d6d
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-shared-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   183920 b2b6944a79df8f5cfea8e864faff1a73
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-usb-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   157516 88a61734f85432779c5437a3256aff7c
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/parport-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    34460 4a5bb06da997b163eabe8d2506276067
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/pata-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    78194 e70a5b2735f1565acfd0dccdd42e02f9
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    86118 2e8ca4c040d8c6f4a51f2064133b8d61
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-storage-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    51170 c9fa04db1560010ef4c393a5a1e0ef08
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/plip-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:     8792 4e53440551c157be34f48106cfccca38
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/ppp-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    64160 79f8e7c6a08ce1882215735cfd1846ee
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/sata-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   101660 b3b6d533bbd7d88cf9bcad3cdc2dd8c8
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/scsi-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:  1448942 8b58e86b771357133c686be093ec88e5
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/serial-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    44504 9a83fcd3376f36a861c5d82f894e1041
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/socket-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    12466 26fb29b1db43062d593f44bb69865785
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/storage-core-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   370290 db295ecbc011997bb66d83c69006a1c1
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/usb-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:   187670 8ef20029cc61364b9df6c182da1dd8b8
    http://security.ubuntu.com/ubuntu/pool/main/l/linux/virtio-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
      Size/MD5:    12974 087166c052778fbe0c10e72cc9b3ffe8


Download attachment "signature.asc" of type "application/pgp-signature" (236 bytes)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ