Ubuntu 12.10 : linux vulnerabilities (USN-2178-1)

Ubuntu Security Notice (C) 2014 Canonical, Inc. / NASL script (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related patches.

Description :

A flaw was discovered in the Kernel Virtual Machine (KVM) subsystem of
the Linux kernel. A guest OS user could exploit this flaw to execute
arbitrary code on the host OS. (CVE-2014-0049)

Al Viro discovered an error in how CIFS in the Linux kernel handles
uncached write operations. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash), obtain
sensitive information from kernel memory, or possibly gain privileges.
(CVE-2014-0069).

Solution :

Update the affected linux-image-3.5.0-49-generic and / or
linux-image-3.5.0-49-highbank packages.

Risk factor :

High / CVSS Base Score : 7.4
(CVSS2#AV:A/AC:M/Au:S/C:C/I:C/A:C)
CVSS Temporal Score : 6.4
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 73727 ()

Bugtraq ID: 65588
65909

CVE ID: CVE-2014-0049
CVE-2014-0069