Oval Definition:oval:com.ubuntu.precise:def:20140069000
Revision Date:2014-02-28Version:1
Title:CVE-2014-0069 on Ubuntu 12.04 LTS (precise) - medium.
Description:The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory corruption and system crash), or possibly gain privileges via a writev system call with a crafted pointer. Al Viro discovered an error in how CIFS in the Linux kernel handles uncached write operations. An unprivileged local user could exploit this flaw to cause a denial of service (system crash), obtain sensitive information from kernel memory, or possibly gain privileges.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-0069
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND Package Information
  • The 'linux' package in precise was vulnerable but has been fixed (note: '3.2.0-63.95').
  • OR The 'linux-armadaxp' package in precise was vulnerable but has been fixed (note: '3.2.0-1633.47').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR The 'linux-lts-quantal' package in precise was vulnerable but has been fixed (note: '3.5.0-49.73~precise1').
  • OR The 'linux-lts-raring' package in precise was vulnerable but has been fixed (note: '3.8.0-39.57~precise1').
  • OR The 'linux-lts-saucy' package in precise was vulnerable but has been fixed (note: '3.11.0-20.34~precise1').
  • OR NOT While related to the CVE in some way, the 'linux-lts-trusty' package in precise is not affected (note: '3.13.0-24.46~precise1').
  • OR While related to the CVE in some way, a decision has been made to ignore it (note: 'abandoned').
  • OR The 'linux-ti-omap4' package in precise was vulnerable but has been fixed (note: '3.2.0-1446.65').
  • BACK