OLS3's underground

May 18, 2012

Linuxsecurity.com

Facebook Hacker Gets a Year in Jail

<b>LinuxSecurity.com</b>: A British hacker who accessed a U.S. citizen's Facebook account has been given a year-long prison sentence.

May 18, 2012 09:38 AM

Drunken 'Call of Duty' hacker jailed for selling gamers' info

<b>LinuxSecurity.com</b>: A 20-year-old British man will spend the next 18 months behind bars for stealing "Call of Duty" gamers' credit card numbers and other confidential data and selling it to other cybercriminals.

May 18, 2012 09:37 AM

May 17, 2012

Linuxsecurity.com

Ubuntu: 1445-1: Linux kernel vulnerabilities

<b>LinuxSecurity.com</b>: Several security issues were fixed in the kernel.

May 17, 2012 09:36 PM

Ubuntu: 1445-1: Linux kernel vulnerabilities

<b>LinuxSecurity.com</b>: Several security issues were fixed in the kernel.

May 17, 2012 08:42 PM

CVE

CVE-2011-3637 (linux_kernel)

The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.

May 17, 2012 08:00 PM

CVE-2011-4131 (linux_kernel)

The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.

May 17, 2012 08:00 PM

CVE-2011-4112 (linux_kernel)

The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.

May 17, 2012 08:00 PM

CVE-2011-4097 (linux_kernel)

Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.

May 17, 2012 08:00 PM

CVE-2011-4594 (linux_kernel)

The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.

May 17, 2012 08:00 PM

CVE-2011-4326 (linux_kernel)

The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.

May 17, 2012 08:00 PM

CVE-2012-0038 (linux_kernel)

Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.

May 17, 2012 08:00 PM

CVE-2011-4621 (linux_kernel)

The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.

May 17, 2012 08:00 PM

CVE-2011-4611 (linux_kernel)

Integer overflow in the perf_event_interrupt function in arch/powerpc/kernel/perf_event.c in the Linux kernel before 2.6.39 on powerpc platforms allows local users to cause a denial of service (unhandled performance monitor exception) via vectors that trigger certain outcomes of performance events.

May 17, 2012 08:00 PM

CVE-2012-0058 (linux_kernel)

The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.

May 17, 2012 08:00 PM

CVE-2012-0044 (linux_kernel)

Integer overflow in the drm_mode_dirtyfb_ioctl function in drivers/gpu/drm/drm_crtc.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.1.5 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted ioctl call.

May 17, 2012 08:00 PM

CVE-2012-0879 (linux_kernel)

The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.

May 17, 2012 08:00 PM

CVE-2012-0207 (linux_kernel)

The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.

May 17, 2012 08:00 PM

CVE-2012-1097 (linux_kernel)

The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.

May 17, 2012 08:00 PM

CVE-2012-1090 (linux_kernel)

The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.

May 17, 2012 08:00 PM

CVE-2012-1179 (linux_kernel)

The Linux kernel before 3.3.1, when KVM is used, allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative access to the guest OS, related to the pmd_none_or_clear_bad function and page faults for huge pages.

May 17, 2012 08:00 PM

CVE-2012-1146 (linux_kernel)

The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.

May 17, 2012 08:00 PM

CVE-2012-2123 (linux_kernel)

The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities (aka fcaps) for implementing a privileged executable file, which allows local users to bypass intended personality restrictions via a crafted application, as demonstrated by an attack that uses a parent process to disable ASLR.

May 17, 2012 08:00 PM

CVE-2012-2121 (linux_kernel)

The KVM implementation in the Linux kernel before 3.3.4 does not properly manage the relationships between memory slots and the iommu, which allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative access to the guest OS to conduct hotunplug and hotplug operations on devices.

May 17, 2012 08:00 PM

CVE-2012-1601 (linux_kernel)

The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.

May 17, 2012 08:00 PM

CVE-2012-2319 (linux_kernel)

Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.

May 17, 2012 08:00 PM

Linuxsecurity.com

Debian: 2475-1: openssl: integer underflow

<b>LinuxSecurity.com</b>: It was discovered that openssl did not correctly handle explicit Initialization Vectors for CBC encryption modes, as used in TLS 1.1, 1.2, and DTLS. An incorrect calculation would lead to an integer underflow and incorrect memory access, causing denial of service [More...]

May 17, 2012 07:16 PM

Ubuntu: 1444-1: BackupPC vulnerability

<b>LinuxSecurity.com</b>: BackupPC could be made to expose sensitive information over the network.

May 17, 2012 06:55 PM

Ubuntu: 1443-1: Update Manager vulnerabilities

<b>LinuxSecurity.com</b>: Update Manager could expose sensitive information in certain circumstances.

May 17, 2012 02:54 PM

Mandriva: 2012:078: imagemagick

<b>LinuxSecurity.com</b>: Multiple vulnerabilities has been found and corrected in imagemagick: A flaw was found in the way ImageMagick processed images with malformed Exchangeable image file format (Exif) metadata. An attacker could create a specially-crafted image file that, when opened by a victim, [More...]

May 17, 2012 09:45 AM

May 16, 2012

Linuxsecurity.com

Pirate Bay Under DDoS Attack From Unknown Enemy

<b>LinuxSecurity.com</b>: With court-ordered ISP blockades popping up all over Europe, The Pirate Bay is no stranger to being silenced. However, for the last 24 hours the site has been largely inaccessible world wide due to a completely different type of censorship. After the site openly criticized Anonymous last week for DDoS'ing UK ISP Virgin Media, The Pirate Bay itself is now under attack.

May 16, 2012 10:00 PM