Huddled Masses
You can do more than breathe for free...
Browse: Home / Linux vulnerability this time!

Linux vulnerability this time!

By Joel 'Jaykul' Bennett on 08-Dec-2003

It’s true! [ 8-O ] ... Actually, this is old news, and hopefully all the distributors have released patches allowing you to upgrade to the 2.4.23 version of the kernel (which you should do now, if you haven’t already).

The critical vulnerability in the Linux kernel actually enables an attacker to gain root access (that is, complete control, in case you don’t speak ‘nix) through a flaw in the Linux kernel itself, which means it affects basically every distribution of the operating system previous to 2.4.23 (or 2.5.69 if you’re running that series of the kernel, or 2.6.0-test6 … golly, doncha love how clear everything is in the linux world?).

It involves an integer overflow in the do_brk() code, and I know for sure that redhat and SUSE have released patches, and of course, Debian since it was they who publicized the vulnerability, after someone used it to compromise several of their servers late last month.

Of course, the good news is how openly and quickly this was handled, once they got hacked. The bad news is that they knew about the vulnerability as long ago as September, and had even fixed it in some pre-release code, but they didn’t think it was important until someone used it to hack their production servers.

Similar Posts:

    None Found

| Tagged Software

« Previous Next »

Lijit Search

Tags

.Net .Net 2008 Scripting Games Automation Bugs Design Development Funny Gadgets GeoShell GUI Huddled Masses Internet licensing Microsoft Modules My Software News Personal PInvoke Pipeline Politics PoshCode PoshConsole PowerBoots PowerShell PowerShell Functions PowerTips Rants Recommender Repository Scripting ShowUI Software Solutions Textile Tips User Group UserInterface WalkThrough WebHosting Windows 7 WordPress WPF Xml

About Huddled Masses

This is web site is dedicated to the musings of Joel Bennett (aka Jaykul) about technology, software, software development, the web, and the world.

Any resemblance of the views expressed and the views of my employer, my terminal, or the view out my window are purely coincidental. The resemblance between them and my own views is non-deterministic. The question of the existence of views in the absence of anyone to hold them is left as an exercise for the reader.

P.S.: I occasionally link to things I think are great. When I do, I occasionally find a "referral code" so I can make a little cash. I promise that I don't link to anything just because of that cash (I wouldn't cross the street for the amount of cash those links bring in, never mind write a whole blog post) ... but I do not promise that things I link to will stay great as time passes, nor that you will agree with me about their greatness!

Archives

  • April 2012
  • February 2012
  • January 2012
  • October 2011
  • August 2011
  • July 2011
  • June 2011
  • March 2011
  • February 2011
  • January 2011

Copyright © 2012 Joel Bennett.

Powered by WordPress and Hybrid.