[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Kernel root exploit en Debian?


En http://linux.oreillynet.com/pub/a/linux/2001/10/22/insecurities.html
hablan de un root exploit [1] ya parchado en RedHat, Caldera y otros. 
Sin embargo no recibi aun un DSA al respecto.  Los que usamos potato con
2.2.19... como estamos?  Alguien sabe si ésto está solucionado?



Some Linux kernels have vulnerabilities that can be exploited to gain
root access and be used in a denial-of-service attack. It is reported
that Linux kernels 2.2.19 and earlier in the 2.2.x series, and 2.4.9 and
earlier in the 2.4.x series, are vulnerable.

The vulnerability that can be used to gain root permissions is exploited
by ptrace and a set user id program. When it is exploited, arbitrary
code will be executed with root permissions. A script to automate the
exploit using the newgrp command has been released.

The denial-of-service attack is caused by making the kernel de-reference
multiple symbolic links. The Linux Kernel version 2.4.10 has a partial
fix for this vulnerability. A script has also been released that can be
used to automate the denial-of-service attack.

Reply to: