| /// File Name: | USN-637-1.txt | Description:
| Ubuntu Security Notice 637-1 - It was discovered that there were multiple NULL-pointer function dereferences in the Linux kernel terminal handling code. A local attacker could exploit this to execute arbitrary code as root, or crash the system, leading to a denial of service. The do_change_type routine did not correctly validation administrative users. A local attacker could exploit this to block mount points or cause private mounts to be shared, leading to denial of service or a possible loss of privacy. Tobias Klein discovered that the OSS interface through ALSA did not correctly validate the device number. A local attacker could exploit this to access sensitive kernel memory, leading to a denial of service or a loss of privacy. Zoltan Sogor discovered that new directory entries could be added to already deleted directories. A local attacker could exploit this, filling up available memory and disk space, leading to a denial of service. | | Homepage: | http://security.ubuntu.com/ | | File Size: | 191184 | | Related CVE(s): | CVE-2008-2812, CVE-2008-2931, CVE-2008-3272, CVE-2008-3275 | | Last Modified: | Aug 26 21:53:24 2008 | | MD5 Checksum: | 4ff77f698b3af8e2303260d5110f0d63 |
|