==========================================================================
Ubuntu Security Notice USN-3186-1
February 01, 2017
iucode-tool vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 16.10
– Ubuntu 16.04 LTS
Summary:
iucode-tool could be made to crash or run programs if it opened a specially
crafted file.
Software Description:
– iucode-tool: Intel processor microcode tool
Details:
It was discovered that iucode-tool incorrectly handled certain microcodes
when using the -tr loader. If a user were tricked into processing a
specially crafted microcode, a remote attacker could use this issue to
cause iucode-tool to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.10:
iucode-tool 1.6.1-1ubuntu0.1
Ubuntu 16.04 LTS:
iucode-tool 1.5.1-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-3186-1
CVE-2017-0357
Package Information:
https://launchpad.net/ubuntu/+source/iucode-tool/1.6.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/iucode-tool/1.5.1-1ubuntu0.1
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2
iQIcBAEBCgAGBQJYkjITAAoJEGVp2FWnRL6TjhAP/3X7MihuZjNybnRmvdYTVWMY
NumODA/ohBPZO+AMO4Kt1SqQWMNbzfSVXlJOx6HJM7nloVfbgJI1ZTc2vK6QgQCp
vR8LruPkqaF1gnAAEr1Vv2l0aGoGAnhFrtpeuYfv2HS2E+bWgo4H9wdDCK9zWOCg
44QibM1jiIj6IgXasc0auNwwbWEOyN+yqmzfPEYxZC1sDkR4u/loNXcquVEbtw+D
rKNK0xPb/gEbPiZOy6ztLSVN0Twf42sN8XQ46tPJpCRLsWY+ZihZ3Ujinl7MrS6/
np3ROjwa5hvqWQsj/YSMiw9ECu1+hMddde1hZ/Bfq6J3fWaZIJbZnBj1v4yFbA6v
AaEOhIfh5dNV1VGar+IkGEzUYQI2vdREiXQFqXTkUU2yfP4H61vQdzqhLkeWRnE1
CwwNSGIRnIiDcLKNcNRxAD21JbUo1eP30ryy/GA/ICSsYHA/El6AYAWKU8Tc5ohc
rW1VQhhpgoQjRtJiF7pIqzl+cZljfpcEaPTZQfUvy8wL+LU9nn3Kxxgu1Dr3+2DF
H/RN3vRHOexvuDiuK1l2MxaWUowE3SAFvUL7hUIexUZcloT3zdz+et6GO2/dzG9t
47QLYcZb0mOuz44JycT3CSVOxpewCw4Lcs3mcXVbjnYOnVH5fmUyhzJkDQUq5YP+
+6ZlmGiDLWYOthu8wkk+
=+EUF
—–END PGP SIGNATURE—–
—