aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorBen Hutchings <ben@decadent.org.uk>2020-10-28 14:56:16 +0000
committerCarsten Schoenert <c.schoenert@t-online.de>2020-10-31 07:28:59 +0100
commit5fbf8d4a1efd1f97a8e8e756acbe29c729555969 (patch)
tree0b410fa8480f44141b7a5f5f23e264cddb604735
parent48139faa7f7196d09383c7f2b7915c0586f1bb84 (diff)
Add DLA-2417-1
-rw-r--r--english/lts/security/2020/dla-2417.data10
-rw-r--r--english/lts/security/2020/dla-2417.wml63
2 files changed, 73 insertions, 0 deletions
diff --git a/english/lts/security/2020/dla-2417.data b/english/lts/security/2020/dla-2417.data
new file mode 100644
index 00000000000..21c0532f90f
--- /dev/null
+++ b/english/lts/security/2020/dla-2417.data
@@ -0,0 +1,10 @@
+<define-tag pagetitle>DLA-2417-1 linux-4.19</define-tag>
+<define-tag report_date>2020-10-28</define-tag>
+<define-tag secrefs>CVE-2020-12351 CVE-2020-12352 CVE-2020-25211 CVE-2020-25643 CVE-2020-25645 Bug#908712</define-tag>
+<define-tag packages>linux-4.19</define-tag>
+<define-tag isvulnerable>yes</define-tag>
+<define-tag fixed>yes</define-tag>
+<define-tag fixed-section>no</define-tag>
+
+#use wml::debian::security
+
diff --git a/english/lts/security/2020/dla-2417.wml b/english/lts/security/2020/dla-2417.wml
new file mode 100644
index 00000000000..5bcdc7aaeed
--- /dev/null
+++ b/english/lts/security/2020/dla-2417.wml
@@ -0,0 +1,63 @@
+<define-tag description>LTS security update</define-tag>
+<define-tag moreinfo>
+<p>Several vulnerabilities have been discovered in the Linux kernel that
+may lead to the execution of arbitrary code, privilege escalation,
+denial of service or information leaks.</p>
+
+<ul>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-12351">CVE-2020-12351</a>
+
+ <p>Andy Nguyen discovered a flaw in the Bluetooth implementation in the
+ way L2CAP packets with A2MP CID are handled. A remote attacker in
+ short distance knowing the victim's Bluetooth device address can
+ send a malicious l2cap packet and cause a denial of service or
+ possibly arbitrary code execution with kernel privileges.</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-12352">CVE-2020-12352</a>
+
+ <p>Andy Nguyen discovered a flaw in the Bluetooth implementation. Stack
+ memory is not properly initialised when handling certain AMP
+ packets. A remote attacker in short distance knowing the victim's
+ Bluetooth device address address can retrieve kernel stack
+ information.</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-25211">CVE-2020-25211</a>
+
+ <p>A flaw was discovered in netfilter subsystem. A local attacker
+ able to inject conntrack Netlink configuration can cause a denial
+ of service.</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-25643">CVE-2020-25643</a>
+
+ <p>ChenNan Of Chaitin Security Research Lab discovered a flaw in the
+ hdlc_ppp module. Improper input validation in the ppp_cp_parse_cr()
+ function may lead to memory corruption and information disclosure.</p></li>
+
+<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-25645">CVE-2020-25645</a>
+
+ <p>A flaw was discovered in the interface driver for GENEVE
+ encapsulated traffic when combined with IPsec. If IPsec is
+ configured to encrypt traffic for the specific UDP port used by the
+ GENEVE tunnel, tunneled data isn't correctly routed over the
+ encrypted link and sent unencrypted instead.</p></li>
+
+</ul>
+
+<p>For Debian 9 stretch, these problems have been fixed in version
+4.19.152-1~deb9u1.</p>
+
+<p>We recommend that you upgrade your linux-4.19 packages.</p>
+
+<p>For the detailed security status of linux-4.19 please refer to
+its security tracker page at:
+<a href="https://security-tracker.debian.org/tracker/linux-4.19">https://security-tracker.debian.org/tracker/linux-4.19</a></p>
+
+<p>Further information about Debian LTS security advisories, how to apply
+these updates to your system and frequently asked questions can be
+found at: <a href="https://wiki.debian.org/LTS">https://wiki.debian.org/LTS</a></p>
+</define-tag>
+
+# do not modify the following line
+#include "$(ENGLISHDIR)/lts/security/2020/dla-2417.data"
+# $Id: $

© 2014-2024 Faster IT GmbH | imprint | privacy policy