Thread: Regarding CVE-2009-1389
"details follow:
michael tokarev discovered rtl8169 network driver did not
correctly validate buffer sizes. remote attacker on local network
send specially traffic traffic crash system or
potentially grant elevated privileges. (cve-2009-1389)
julien tinnes , tavis ormandy discovered when executing setuid
processes kernel did not clear personality flags. local
attacker exploit map null memory page, causing other
vulnerabilities become exploitable. ubuntu 6.06 not affected.
(cve-2009-1895)
matt t. yourst discovered kvm did not correctly validate the
page table root. local attacker exploit crash the
system, leading denial of service. ubuntu 6.06 not affected.
(cve-2009-2287)
ramon de carvalho valle discovered ecryptfs did not correctly
validate buffer sizes. local attacker create specially
crafted ecryptfs files crash system or gain elevated privileges.
ubuntu 6.06 not affected. (cve-2009-2406, cve-2009-2407)"
have nic
root@ubu02:/# lspci -vvv | grep ethernet
03:00.0 ethernet controller: broadcom corporation netxtreme ii bcm5708 gigabit ethernet (rev 12)
07:00.0 ethernet controller: broadcom corporation netxtreme ii bcm5708 gigabit ethernet (rev 12)
means safe? how can figure out if running
driver?
cve-2009-1895 should upgrade or not? not seem
dangerous.
it looks nic uses broadcom chipset, don't think problem. see if rtl8169 driver loaded open terminal , type:
the above command tell if drivers loaded.code:lsmod | grep rtl8169
Forum The Ubuntu Forum Community Ubuntu Specialised Support Security [ubuntu] Regarding CVE-2009-1389
Ubuntu
Comments
Post a Comment