![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.68184 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu USN-1001-1 (lvm2) |
Summary: | NOSUMMARY |
Description: | Description: The remote host is missing an update to lvm2 announced via advisory USN-1001-1. A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10 Ubuntu 10.04 LTS Details follow: The cluster logical volume manager daemon (clvmd) in LVM2 did not correctly validate credentials. A local user could use this flaw to manipulate logical volumes without root privileges and cause a denial of service in the cluster. Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: clvm 2.02.02-1ubuntu1.6 Ubuntu 8.04 LTS: clvm 2.02.26-1ubuntu9.1 Ubuntu 9.04: clvm 2.02.39-0ubuntu9.1 Ubuntu 9.10: clvm 2.02.39-0ubuntu11.1 Ubuntu 10.04 LTS: clvm 2.02.54-1ubuntu4.1 In general, a standard system update will make all the necessary changes. In a clustering environment, you need to restart clvmd after the update. https://secure1.securityspace.com/smysecure/catid.html?in=USN-1001-1 Risk factor : Medium CVSS Score: 4.6 |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2526 1024258 http://securitytracker.com/id?1024258 40759 http://secunia.com/advisories/40759 66753 http://www.osvdb.org/66753 ADV-2010-1944 http://www.vupen.com/english/advisories/2010/1944 RHSA-2010:0567 https://rhn.redhat.com/errata/RHSA-2010-0567.html RHSA-2010:0568 https://rhn.redhat.com/errata/RHSA-2010-0568.html SUSE-SR:2010:017 http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html USN-1001-1 http://www.ubuntu.com/usn/USN-1001-1 [linux-lvm] 20100728 lvm2-cluster (clvmd) security fix (Moderate) https://www.redhat.com/archives/linux-lvm/2010-July/msg00083.html https://bugzilla.redhat.com/show_bug.cgi?id=614248 lvm2-socket-privilege-escalation(60809) https://exchange.xforce.ibmcloud.com/vulnerabilities/60809 |
Copyright | Copyright (c) 2010 E-Soft Inc. http://www.securityspace.com |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |