Matt Posted July 7, 2013 Report Posted July 7, 2013 Description : Ubuntu Security Notice 1900-1 - Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem that can expose stale data. An unprivileged user could exploit this flaw to cause an information leak. An information leak was discovered in the Linux kernel's tkill and tgkill system calls when used from compat processes. A local user could exploit this flaw to examine potentially sensitive kernel memory. A format string vulnerability was discovered in Broadcom B43 wireless driver for the Linux kernel. A local user could exploit this flaw to gain administrative privileges. Various other issues were also addressed.Author : UbuntuSource : Ubuntu Security Notice USN-1900-1 ? Packet StormCode : ============================================================================Ubuntu Security Notice USN-1900-1July 04, 2013linux-ec2 vulnerabilities============================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 10.04 LTSSummary:Several security issues were fixed in the kernel.Software Description:- linux-ec2: Linux kernel for EC2Details:Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystemthat can expose stale data. An unprivileged user could exploit this flaw tocause an information leak. (CVE-2012-4508)An information leak was discovered in the Linux kernel's tkill and tgkillsystem calls when used from compat processes. A local user could exploitthis flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)A format string vulnerability was discovered in Broadcom B43 wirelessdriver for the Linux kernel. A local user could exploit this flaw to gainadministrative privileges. (CVE-2013-2852)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 10.04 LTS: linux-image-2.6.32-354-ec2 2.6.32-354.67After a standard system update you need to reboot your computer to makeall the necessary changes.ATTENTION: Due to an unavoidable ABI change the kernel updates havebeen given a new version number, which requires you to recompile andreinstall all third party kernel modules you might have installed. Ifyou use linux-restricted-modules, you have to update that package aswell to get modules which work with the new kernel version. Unless youmanually uninstalled the standard kernel metapackages (e.g. linux-generic,linux-server, linux-powerpc), a standard system upgrade will automaticallyperform this as well.References: http://www.ubuntu.com/usn/usn-1900-1 CVE-2012-4508, CVE-2013-2141, CVE-2013-2852Package Information: https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-354.67 Quote