Lucene search

K
ubuntuUbuntuUSN-1728-1
HistoryFeb 19, 2013 - 12:00 a.m.

Linux kernel (EC2) vulnerability

2013-02-1900:00:00
ubuntu.com
43

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%

Releases

  • Ubuntu 10.04

Packages

  • linux-ec2 - Linux kernel for EC2

Details

Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously.

OSVersionArchitecturePackageVersionFilename
Ubuntu10.04noarchlinux-image-2.6.32-350-ec2< 2.6.32-350.60UNKNOWN
Ubuntu10.04noarchlinux-headers-2.6.32-350-ec2< 2.6.32-350.60UNKNOWN

CVSS2

4.9

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

5.1%