-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2019.0099
          Intel Graphics Performance Analyzer for Linux Advisory
                               10 April 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Intel Graphics Performance Analyzer for Linux
Operating System:     Linux variants
Impact/Access:        Increased Privileges -- Existing Account
Resolution:           Patch/Upgrade
CVE Names:            CVE-2019-0158  
Member content until: Friday, May 10 2019

OVERVIEW

        Intel has discovered a vulnerability in Intel Graphics Performance 
        Analyzer for Linux. [1]


IMPACT

        Intel has provided the following information regarding the 
        vulnerability:
        
        "Vulnerability Details:
        
        CVEID: CVE-2019-0158
        
        Description: Insufficient path checking in the installation package
        for Intel (R) Graphics Performance Analyzer for Linux version 18.4 
        and before may allow an authenticated user to potentially enable 
        escalation of privilege via local access.
        
        CVSS Base Score: 6.7 Medium
        
        CVSS Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
        
        Affected Products:
        
        Intel Graphics Performance Analyzer for Linux version 18.4 and 
        before." [1]


MITIGATION

        Intel recommends affected users take the following steps:
        
        "Intel recommends that users of Intel Graphics Performance Analyzer for Linux
        update to 2019 R1.
        
        Updates are available for download at this location:
        
        https://software.intel.com/en-us/gpa/free-download
        
        For more information please refer to the release notes at:
        
        https://software.intel.com/en-us/articles/
        intel-graphics-performance-analyzers-release-notes" [1]


REFERENCES

        [1] Intel Graphics Performance Analyzer for Linux Advisory
            https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00236.html

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXK2MBWaOgq3Tt24GAQgqNQ//YcgAbhtxprElZjp8XkawS0XL316Pfb8/
3aML9aE55fhGxeWX4rY8DeLfMJrOn1f+Sjb2CWN5Y0jZ/9CS6+IjJr92xS2LBJQt
X9XtkvW6Qe8xn6EMuN39CLawmLa2FCfzre70YKHt0sKie+OMPJxTHz5gyaEnwe6f
tnQE+Kl7uLY36sHe5fg5BfT8+jCCi3qlzSb5+n4NbbOZn3jusjfjr8hin5g4sioH
Kgprf+iqmOxJU5LeiZiI/aavRbJZ4uLg+DhZYTWKLd8yT8GYhk3oRi/CUYEXHhLv
x8XgjNeXhJoIH+OPf1V5tSUUIbVmTSEFZv2vBWUsNQ1wMWsh8LjENBIAjHw8OObb
yqJTfuetn4p1UIBM+FibH7UEV8mRd89T2wa/zNewA0+UciKUhz01lnteQ6K5SyWu
sk1jTX7KuDNwUmHOH1n7kuTjB5dukcGvJcRi+yr7zUFCK4QUvGu22S/rjyQXh3g4
FT+jTNlHVyBc/5m1tFWtDGEY4ax+ORkz4AXjYRpY12b30/A0M73CFwqAoh8k2Yqc
nL20JDjyi4SV7YBQWUzWctOq3L++K3uvhoDGamYis4pKSP5sxcQmZsnguqaRP6fm
aAmMLnVP/HbtRlClCE7sKkC7c6Jn19tgLbeJmkkT1X9nmYArJs1vT0dNDDY9vgkS
wX/7K5lfnZk=
=APeV
-----END PGP SIGNATURE-----