To print: Click here or Select File and then Print from your browser's menu
This story was printed from silicon.com, located at http://www.silicon.com/
Story URL: http://software.silicon.com/os/0,39024651,39275144,00.htm
Ubuntu patches flaw
Time to update...
By Renai LeMay
Published: Tuesday 26 August 2008
Ubuntu became the latest Linux vendor to patch a vulnerability in the open-source operating system's kernel that could have left the door open for hackers to find their way into users' machines.
In an email sent last night, the Linux vendor warned users to update all machines running recent versions of Ubuntu, ranging from 6.06, which was released back in mid-2006, to version 8.04, which came out earlier this year. The problem also applied to other versions of Ubuntu such as Kubuntu, Edubuntu and Xubuntu.
Ubuntu administrators wrote in the email: "It was discovered that there were multiple NULL-pointed function de-references in the Linux kernel terminal handling code. A local attacker could exploit this to execute arbitrary code as root, or crash the system, leading to a denial of service."
The email also detailed a number of other bugs which could be exploited by an attacker who already had some level of access to a computer running Ubuntu.
A number of other Linux vendors including Novell have recently released similar patches to address the problems.
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page