Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.843376
Category:Ubuntu Local Security Checks
Title:Ubuntu Update for linux USN-3487-1
Summary:The remote host is missing an update for the 'linux'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'linux'
package(s) announced via the referenced advisory.

Vulnerability Insight:
It was discovered that the KVM subsystem in
the Linux kernel did not properly keep track of nested levels in guest page
tables. A local attacker in a guest VM could use this to cause a denial of
service (host OS crash) or possibly execute arbitrary code in the host OS.
(CVE-2017-12188) It was discovered that on the PowerPC architecture, the kernel
did not properly sanitize the signal stack when handling sigreturn(). A local
attacker could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2017-1000255) Bo Zhang discovered that the netlink
wireless configuration interface in the Linux kernel did not properly validate
attributes when handling certain requests. A local attacker with the
CAP_NET_ADMIN could use this to cause a denial of service (system crash).
(CVE-2017-12153) It was discovered that the nested KVM implementation in the
Linux kernel in some situations did not properly prevent second level guests
from reading and writing the hardware CR8 register. A local attacker in a guest
could use this to cause a denial of service (system crash). (CVE-2017-12154)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel did not
properly track reference counts when merging buffers. A local attacker could use
this to cause a denial of service (memory exhaustion). (CVE-2017-12190) It was
discovered that the key management subsystem in the Linux kernel did not
properly restrict key reads on negatively instantiated keys. A local attacker
could use this to cause a denial of service (system crash). (CVE-2017-12192) It
was discovered that the ATI Radeon framebuffer driver in the Linux kernel did
not properly initialize a data structure returned to user space. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2017-14156) ChunYu Wang discovered that the iSCSI transport implementation
in the Linux kernel did not properly validate data structures. A local attacker
could use this to cause a denial of service (system crash). (CVE-2017-14489)
Alexander Potapenko discovered an information leak in the waitid implementation
of the Linux kernel. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2017-14954) It was discovered that a race
condition existed in the ALSA subsystem of the Linux kernel when creating and
deleting a port via ioctl(). A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code. (CVE-2017-15265)
Dmitry Vyukov discovered that the Floating Point Unit (fpu) subsystem in the
Linux kernel did not properly handl ... Description truncated, for more
information please check the Reference URL

Affected Software/OS:
linux on Ubuntu 17.10

Solution:
Please Install the Updated Packages.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-12188
Common Vulnerability Exposure (CVE) ID: CVE-2017-1000255
Common Vulnerability Exposure (CVE) ID: CVE-2017-12153
Common Vulnerability Exposure (CVE) ID: CVE-2017-12154
Common Vulnerability Exposure (CVE) ID: CVE-2017-12190
Common Vulnerability Exposure (CVE) ID: CVE-2017-12192
Common Vulnerability Exposure (CVE) ID: CVE-2017-14156
Common Vulnerability Exposure (CVE) ID: CVE-2017-14489
Common Vulnerability Exposure (CVE) ID: CVE-2017-14954
Common Vulnerability Exposure (CVE) ID: CVE-2017-15265
Common Vulnerability Exposure (CVE) ID: CVE-2017-15537
Common Vulnerability Exposure (CVE) ID: CVE-2017-15649
Common Vulnerability Exposure (CVE) ID: CVE-2017-16525
Common Vulnerability Exposure (CVE) ID: CVE-2017-16526
Common Vulnerability Exposure (CVE) ID: CVE-2017-16527
Common Vulnerability Exposure (CVE) ID: CVE-2017-16529
Common Vulnerability Exposure (CVE) ID: CVE-2017-16530
Common Vulnerability Exposure (CVE) ID: CVE-2017-16531
Common Vulnerability Exposure (CVE) ID: CVE-2017-16533
Common Vulnerability Exposure (CVE) ID: CVE-2017-16534
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.