Submitted by JamesStrandboge on Tue, 2008-02-12 17:22
Referenced CVEs:
CVE-2008-0600
Description:
===========================================================
Ubuntu Security Notice USN-577-1 February 12, 2008
linux-source-2.6.17/20/22 vulnerability
CVE-2008-0600
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.10:
linux-image-2.6.17-12-386 2.6.17.1-12.44
linux-image-2.6.17-12-generic 2.6.17.1-12.44
linux-image-2.6.17-12-hppa32 2.6.17.1-12.44
linux-image-2.6.17-12-hppa64 2.6.17.1-12.44
linux-image-2.6.17-12-itanium 2.6.17.1-12.44
linux-image-2.6.17-12-mckinley 2.6.17.1-12.44
linux-image-2.6.17-12-powerpc 2.6.17.1-12.44
linux-image-2.6.17-12-powerpc-smp 2.6.17.1-12.44
linux-image-2.6.17-12-powerpc64-smp 2.6.17.1-12.44
linux-image-2.6.17-12-server 2.6.17.1-12.44
linux-image-2.6.17-12-server-bigiron 2.6.17.1-12.44
linux-image-2.6.17-12-sparc64 2.6.17.1-12.44
linux-image-2.6.17-12-sparc64-smp 2.6.17.1-12.44
Ubuntu 7.04:
linux-image-2.6.20-16-386 2.6.20-16.35
linux-image-2.6.20-16-generic 2.6.20-16.35
linux-image-2.6.20-16-hppa32 2.6.20-16.35
linux-image-2.6.20-16-hppa64 2.6.20-16.35
linux-image-2.6.20-16-itanium 2.6.20-16.35
linux-image-2.6.20-16-lowlatency 2.6.20-16.35
linux-image-2.6.20-16-mckinley 2.6.20-16.35
linux-image-2.6.20-16-powerpc 2.6.20-16.35
linux-image-2.6.20-16-powerpc-smp 2.6.20-16.35
linux-image-2.6.20-16-powerpc64-smp 2.6.20-16.35
linux-image-2.6.20-16-server 2.6.20-16.35
linux-image-2.6.20-16-server-bigiron 2.6.20-16.35
linux-image-2.6.20-16-sparc64 2.6.20-16.35
linux-image-2.6.20-16-sparc64-smp 2.6.20-16.35
Ubuntu 7.10:
linux-image-2.6.22-14-386 2.6.22-14.52
linux-image-2.6.22-14-cell 2.6.22-14.52
linux-image-2.6.22-14-generic 2.6.22-14.52
linux-image-2.6.22-14-hppa32 2.6.22-14.52
linux-image-2.6.22-14-hppa64 2.6.22-14.52
linux-image-2.6.22-14-itanium 2.6.22-14.52
linux-image-2.6.22-14-lpia 2.6.22-14.52
linux-image-2.6.22-14-lpiacompat 2.6.22-14.52
linux-image-2.6.22-14-mckinley 2.6.22-14.52
linux-image-2.6.22-14-powerpc 2.6.22-14.52
linux-image-2.6.22-14-powerpc-smp 2.6.22-14.52
linux-image-2.6.22-14-powerpc64-smp 2.6.22-14.52
linux-image-2.6.22-14-rt 2.6.22-14.52
linux-image-2.6.22-14-server 2.6.22-14.52
linux-image-2.6.22-14-sparc64 2.6.22-14.52
linux-image-2.6.22-14-sparc64-smp 2.6.22-14.52
linux-image-2.6.22-14-ume 2.6.22-14.52
linux-image-2.6.22-14-virtual 2.6.22-14.52
linux-image-2.6.22-14-xen 2.6.22-14.52
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
Wojciech Purczynski discovered that the vmsplice system call did
not properly perform verification of user-memory pointers. A local
attacker could exploit this to overwrite arbitrary kernel memory
and gain root privileges. (CVE-2008-0600)


