USN-335-1: heartbeat vulnerability

16 August 2006

heartbeat vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 6.06 LTS
  • Ubuntu 5.10
  • Ubuntu 5.04

Software Description


Yan Rong Ge discovered that heartbeat did not sufficiently verify some packet input data, which could lead to an out-of-boundary memory access. A remote attacker could exploit this to crash the daemon (Denial of Service).

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 6.06 LTS
heartbeat - 1.2.4-2ubuntu0.2
Ubuntu 5.10
heartbeat - 1.2.3-12ubuntu0.2
Ubuntu 5.04
heartbeat - 1.2.3-3ubuntu1.3

To update your system, please follow these instructions:

In general, a standard system upgrade is sufficient to effect the necessary changes.