Submitted by KeesCook on Tue, 2006-07-18 12:05
Referenced CVEs:
CVE-2006-3626
Description:
===========================================================
Ubuntu Security Notice USN-319-1 July 18, 2006
linux-source-2.6.15 vulnerability
CVE-2006-3626
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
linux-image-2.6.15-26-386 2.6.15-26.45
linux-image-2.6.15-26-686 2.6.15-26.45
linux-image-2.6.15-26-amd64-generic 2.6.15-26.45
linux-image-2.6.15-26-amd64-k8 2.6.15-26.45
linux-image-2.6.15-26-amd64-server 2.6.15-26.45
linux-image-2.6.15-26-amd64-xeon 2.6.15-26.45
linux-image-2.6.15-26-hppa32 2.6.15-26.45
linux-image-2.6.15-26-hppa32-smp 2.6.15-26.45
linux-image-2.6.15-26-hppa64 2.6.15-26.45
linux-image-2.6.15-26-hppa64-smp 2.6.15-26.45
linux-image-2.6.15-26-itanium 2.6.15-26.45
linux-image-2.6.15-26-itanium-smp 2.6.15-26.45
linux-image-2.6.15-26-k7 2.6.15-26.45
linux-image-2.6.15-26-mckinley 2.6.15-26.45
linux-image-2.6.15-26-mckinley-smp 2.6.15-26.45
linux-image-2.6.15-26-powerpc 2.6.15-26.45
linux-image-2.6.15-26-powerpc-smp 2.6.15-26.45
linux-image-2.6.15-26-powerpc64-smp 2.6.15-26.45
linux-image-2.6.15-26-server 2.6.15-26.45
linux-image-2.6.15-26-server-bigiron 2.6.15-26.45
linux-image-2.6.15-26-sparc64 2.6.15-26.45
linux-image-2.6.15-26-sparc64-smp 2.6.15-26.45
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
This flaw affects Ubuntu 5.04 and Ubuntu 5.10 as well; these releases
will be fixed shortly in a followup advisory.
Details follow:
A race condition has been discovered in the file permission handling
of the /proc file system. A local attacker could exploit this to
execute arbitrary code with full root privileges.


