Home
Home
    • Blog
    • Clinic
    • Contact
    • Download
    • Video
    • Login

Poll

Favourite console text editor in Ubuntu:

LXer -- Linux and Open Source News

  • Nettop taps Ion 2 GPU
  • Opera releases Mini browser beta for Android
  • Valve Is Not Commenting On Steam, Source Engine For Linux
  • Why Use GRUB2? Good Question! (part 3)
  • Come Out as Part of KDE
more

Linux Today

  • Deferrable functions, kernel tasklets, and work queues
  • Simon Phipps elected as OSI director
  • Beginner’s Guide to Git
  • Day 3 of the Trial, Through the Eyes of Groklaw and the SL Tribune
  • AMD to Introduce Netbook Chip in 2011
more

Linux Insider

  • Ubuntu Dumps the Brown
  • Atol Delivers Flawless File Management With No Frills
more

USN-670-1: VMBuilder vulnerability

Submitted by k4tz on Fri, 11/14/2008 - 11:16
  • Edubuntu
  • Kubuntu
  • Linux World
  • Security
  • Ubuntu
  • Xubuntu

===========================================================
Ubuntu Security Notice USN-670-1 November 13, 2008 vm-builder vulnerability https://bugs.launchpad.net/+bug/296841
===========================================================
A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.10 Ubuntu 8.04 LTS Ubuntu 8.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: passwd 1:4.0.13-7ubuntu3.3 Ubuntu 7.10: passwd 1:4.0.18.1-9ubuntu0.1 Ubuntu 8.04 LTS: passwd 1:4.0.18.2-1ubuntu2.1 Ubuntu 8.10: passwd 1:4.1.1-1ubuntu1.1 python-vm-builder 0.9-0ubuntu3.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Mathias Gug discovered that vm-builder improperly set the root password when creating virtual machines. An attacker could exploit this to gain root privileges to the virtual machine by using a predictable password.
This vulnerability only affects virtual machines created with vm-builder under Ubuntu 8.10, and does not affect native Ubuntu installations. An update was made to the shadow package to detect vulnerable systems and disable password authentication for the root account. Vulnerable virtual machines which an attacker has access to should be considered compromised, and appropriate actions taken to secure the machine.

 

Source: http://www.ubuntu.com/usn/usn-670-1

  • Add new comment

Recent blog posts

  • Configure ThinkPad laptop trackpoint on Ubuntu
  • How to make WPA connection in Ubuntu on demand
  • Review: Sabily 9.10 - Linux Ubuntu for Muslims
  • How to Install 64bit flash on Ubuntu
  • How to get Wireless LAN (Broadcom) on Acer Aspire 4720Z working with Ubuntu 9.10
  • Quick loot at Ubuntu 10.04 Lucid Lynx Alpha 3
  • System testing and benchmarking under Ubuntu 9.10
  • How to PXE booting Ubuntu Installer
  • How to Install Debian onto your Nexus One using Ubuntu
  • (Re) Install a Linux Kernel
more

Linux World

  • Microsoft's Internet Driving Licence: stupid, unworkable and unenforceable
  • Making a videoloop with Kino and Audacity
  • So is ChromeOS a desktop winner? I think not
  • Firefogg: Transcoding videos to open web standards with Mozilla Firefox
  • The Morevna Project: Anime with Synfig and Blender
Archive Syndicate content

Recent comments

  • Re
    9 weeks 4 days ago
  • Re
    9 weeks 4 days ago
  • Re
    10 weeks 4 days ago
  • Re
    11 weeks 11 hours ago
  • Re
    11 weeks 5 days ago
  • Re
    11 weeks 5 days ago
  • Re
    11 weeks 6 days ago
  • iwl3945
    13 weeks 3 days ago
  • HomeBank
    25 weeks 5 days ago
  • KMyMoney and direct connect to banks
    29 weeks 6 days ago
All contents copyright © 2008, Dhuha Net. All rights reserved
Ubuntudoctor® is a member of the Dhuha Network. Privacy Policy
RoopleTheme