Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2019.0099 Intel Graphics Performance Analyzer for Linux Advisory 10 April 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Intel Graphics Performance Analyzer for Linux Operating System: Linux variants Impact/Access: Increased Privileges -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2019-0158 Member content until: Friday, May 10 2019 OVERVIEW Intel has discovered a vulnerability in Intel Graphics Performance Analyzer for Linux. [1] IMPACT Intel has provided the following information regarding the vulnerability: "Vulnerability Details: CVEID: CVE-2019-0158 Description: Insufficient path checking in the installation package for Intel (R) Graphics Performance Analyzer for Linux version 18.4 and before may allow an authenticated user to potentially enable escalation of privilege via local access. CVSS Base Score: 6.7 Medium CVSS Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: Intel Graphics Performance Analyzer for Linux version 18.4 and before." [1] MITIGATION Intel recommends affected users take the following steps: "Intel recommends that users of Intel Graphics Performance Analyzer for Linux update to 2019 R1. Updates are available for download at this location: https://software.intel.com/en-us/gpa/free-download For more information please refer to the release notes at: https://software.intel.com/en-us/articles/ intel-graphics-performance-analyzers-release-notes" [1] REFERENCES [1] Intel Graphics Performance Analyzer for Linux Advisory https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00236.html AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXK2MBWaOgq3Tt24GAQgqNQ//YcgAbhtxprElZjp8XkawS0XL316Pfb8/ 3aML9aE55fhGxeWX4rY8DeLfMJrOn1f+Sjb2CWN5Y0jZ/9CS6+IjJr92xS2LBJQt X9XtkvW6Qe8xn6EMuN39CLawmLa2FCfzre70YKHt0sKie+OMPJxTHz5gyaEnwe6f tnQE+Kl7uLY36sHe5fg5BfT8+jCCi3qlzSb5+n4NbbOZn3jusjfjr8hin5g4sioH Kgprf+iqmOxJU5LeiZiI/aavRbJZ4uLg+DhZYTWKLd8yT8GYhk3oRi/CUYEXHhLv x8XgjNeXhJoIH+OPf1V5tSUUIbVmTSEFZv2vBWUsNQ1wMWsh8LjENBIAjHw8OObb yqJTfuetn4p1UIBM+FibH7UEV8mRd89T2wa/zNewA0+UciKUhz01lnteQ6K5SyWu sk1jTX7KuDNwUmHOH1n7kuTjB5dukcGvJcRi+yr7zUFCK4QUvGu22S/rjyQXh3g4 FT+jTNlHVyBc/5m1tFWtDGEY4ax+ORkz4AXjYRpY12b30/A0M73CFwqAoh8k2Yqc nL20JDjyi4SV7YBQWUzWctOq3L++K3uvhoDGamYis4pKSP5sxcQmZsnguqaRP6fm aAmMLnVP/HbtRlClCE7sKkC7c6Jn19tgLbeJmkkT1X9nmYArJs1vT0dNDDY9vgkS wX/7K5lfnZk= =APeV -----END PGP SIGNATURE-----