[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: My machine was hacked - possibly via sshd?



On Tue, 29 Mar 2005 at 13:18:42 +0000, Maurizio Lemmo - Tannoiser wrote:
> On martedì 29 marzo 2005, alle 00:34, Adam M. wrote:
> > >But 2.4.18 is the Debian stable kernel, which gets security updates
> > >and patches, no?
> > 
> > No, it doesn't. I really think that packages like this old kernel
> > should be removed from the mirrors, or at least updated with big fat
> > warning.
> 
> Sorry, but this isn't correct.  kernel 2.4.18-1 in woody is patched
> against known vulnerability.

The security team have quietly stopped updating it, preferring to
concentrate on the Sarge kernels.

> Recent [vulnerabilities] involve code not present in this release of
> kernel.

Some of them, maybe. But take a look at #289708 for an example of an
unfixed vulnerability in Woody's 2.4.18.

S.



Reply to: