USN-1271-1 : linux-fsl-imx51 vulnerabilities

Ubuntu Security Notice (C) 2011-2012 Canonical, Inc. / NASL script (C) 2011-2012 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related
patches.

Description :

It was discovered that CIFS incorrectly handled authentication. When
a user had a CIFS share mounted that required authentication, a local
user could mount the same share without knowing the correct password.
(CVE-2011-1585)

It was discovered that the GRE protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the
ip_gre module was loading, and crash the system, leading to a denial
of service. (CVE-2011-1767)

It was discovered that the IP/IP protocol incorrectly handled netns
initialization. A remote attacker could send a packet while the ipip
module was loading, and crash the system, leading to a denial of
service. (CVE-2011-1768)

Vasily Averin discovered that the NFS Lock Manager (NLM) incorrectly
handled unlock requests. A local attacker could exploit this to cause
a denial of service. (CVE-2011-2491)

See also :

http://www.ubuntu.com/usn/usn-1271-1/

Solution :

Update the affected package(s).

Risk factor :

Medium / CVSS Base Score : 5.4
(CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C)

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 56913 ()

Bugtraq ID:

CVE ID: CVE-2011-1585
CVE-2011-1767
CVE-2011-1768
CVE-2011-2491