============================================================================ Ubuntu Security Notice USN-1456-1 May 31, 2012 nut vulnerability ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS Summary: Nut could be made to crash if it received specially crafted network traffic. Software Description: - nut: Network UPS tools Details: Sebastian Pohle discovered that Nut did not properly validate its input when receiving data over the network. If upsd was configured to allow connections over the network, a remote attacker could exploit this to cause a denial of service (application crash). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: nut-server 2.6.3-1ubuntu1.1 Ubuntu 11.10: nut-server 2.6.1-2ubuntu2.1 Ubuntu 11.04: nut 2.6.0-1ubuntu3.1 Ubuntu 10.04 LTS: nut 2.4.3-1ubuntu3.2 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1456-1 CVE-2012-2944 Package Information: https://launchpad.net/ubuntu/+source/nut/2.6.3-1ubuntu1.1 https://launchpad.net/ubuntu/+source/nut/2.6.1-2ubuntu2.1 https://launchpad.net/ubuntu/+source/nut/2.6.0-1ubuntu3.1 https://launchpad.net/ubuntu/+source/nut/2.4.3-1ubuntu3.2