Summary
Ubuntu Update for Linux kernel vulnerabilities USN-1115-1
Solution
Please Install the Updated Packages.
Insight
Romain Perier discovered that the language-selector D-Bus backend did not correctly check for Policy Kit authorizations. A local attacker could exploit this to inject shell commands into the system-wide locale configuration file, leading to root privilege escalation.
Affected
language-selector on Ubuntu 10.10
Severity
Classification
-
CVE CVE-2011-0729 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities