SB2018022018 - Information disclosure in Linux kernel
Published: February 20, 2018 Updated: May 30, 2018
Security Bulletin ID
SB2018022018
Severity
Low
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Security restrictions bypass (CVE-ID: CVE-2018-7273)
The vulnerability allows a local attacker to bypass security restrictions and obtain potentially sensitive information on the target system.The weakness exists in the show_floppy function due to insufficient security restrictions. A local attacker can bypass security restrictions and gain access to potentially sensitive information.
2) Information disclosure (CVE-ID: CVE-2018-6412)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.The weakness exists due to integer signedness error in the sbusfb_ioctl_helper function in drivers/video/fbdev/sbuslib.c. A remote attacker can use vector related to the FBIOPUTCMAP_SPARC and FBIOGETCMAP_SPARC commands to access arbitrary data.
Remediation
Install update from vendor's website.