USN-2379-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-2379-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-2379-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2379-1
Related
  • CVE-2014-3181
  • CVE-2014-3184
  • CVE-2014-3185
  • CVE-2014-3186
  • CVE-2014-3631
  • CVE-2014-6410
  • CVE-2014-6416
  • CVE-2014-6417
  • CVE-2014-6418
Published
2014-10-09T11:00:07.107935Z
Modified
2014-10-09T11:00:07.107935Z
Summary
linux vulnerabilities
Details

Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's magicmouse HID driver. A physically proximate attacker could exploit this flaw to cause a denial of service (system crash) or possibly execute arbitrary code via specially crafted devices. (CVE-2014-3181)

Ben Hawkes reported some off by one errors for report descriptors in the Linux kernel's HID stack. A physically proximate attacker could exploit these flaws to cause a denial of service (out-of-bounds write) via a specially crafted device. (CVE-2014-3184)

Several bounds check flaws allowing for buffer overflows were discovered in the Linux kernel's Whiteheat USB serial driver. A physically proximate attacker could exploit these flaws to cause a denial of service (system crash) via a specially crafted device. (CVE-2014-3185)

Steven Vittitoe reported a buffer overflow in the Linux kernel's PicoLCD HID device driver. A physically proximate attacker could exploit this flaw to cause a denial of service (system crash) or possibly execute arbitrary code via a specially craft device. (CVE-2014-3186)

A flaw was discovered in the Linux kernel's associative-array garbage collection implementation. A local user could exploit this flaw to cause a denial of service (system crash) or possibly have other unspecified impact by using keyctl operations. (CVE-2014-3631)

A flaw was discovered in the Linux kernel's UDF filesystem (used on some CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause CD, DVD or image file with a specially crafted inode to be mounted can cause a denial of service (infinite loop or stack consumption). (CVE-2014-6410)

James Eckersall discovered a buffer overflow in the Ceph filesystem in the Linux kernel. A remote attacker could exploit this flaw to cause a denial of service (memory consumption and panic) or possibly have other unspecified impact via a long unencrypted auth ticket. (CVE-2014-6416)

James Eckersall discovered a flaw in the handling of memory allocation failures in the Ceph filesystem. A remote attacker could exploit this flaw to cause a denial of service (system crash) or possibly have unspecified other impact. (CVE-2014-6417)

James Eckersall discovered a flaw in how the Ceph filesystem validates auth replies. A remote attacker could exploit this flaw to cause a denial of service (system crash) or possibly have other unspecified impact. (CVE-2014-6418)

References

Affected packages

Ubuntu:14.04:LTS / linux

Package

Name
linux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.0-37.64

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "linux-image-3.13.0-37-generic-lpae": "3.13.0-37.64",
            "linux-image-3.13.0-37-powerpc64-smp": "3.13.0-37.64",
            "linux-image-3.13.0-37-lowlatency": "3.13.0-37.64",
            "linux-image-extra-3.13.0-37-generic": "3.13.0-37.64",
            "linux-image-3.13.0-37-powerpc-smp": "3.13.0-37.64",
            "linux-image-3.13.0-37-powerpc-e500": "3.13.0-37.64",
            "linux-image-3.13.0-37-powerpc-e500mc": "3.13.0-37.64",
            "linux-image-3.13.0-37-powerpc64-emb": "3.13.0-37.64",
            "linux-image-3.13.0-37-generic": "3.13.0-37.64"
        }
    ]
}