do_path() bug is not remotely or local non-root exploitable

Harald Welte <[email protected]> Wed, 22 Mar 2006 11:59:34 +0100
Newsgroups gmane.comp.security.firewalls.netfilter.announce
Message-ID <20060322105934.GO21238__10203.1690454625$1143025399$gmane$org@sunbeam.de.gnumonks.org>
Hi!

JFYI, see the attachment.

Securityfocus and some other news sites have spread rumour that the
do_path() bug fixed with 2.6.16 is remotely exploitable.

It is not.

Unless you are using virtualization techniques like Virtuozzo or
Vserver (where 'root' cannot neccessarily be trusted), there is not
really any security risk caused by this bug.  Stay cool.

Cheers,
	Harald (for the netfilter core team)

-- 
- Harald Welte <[email protected]>                 http://netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie
(unnamed) (message/rfc822, 2.6 KB) - not displayed
signature.asc (application/pgp-signature, 191 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFEIS4WXaXGVTD0i/8RAtZAAJ47tzbsee984mJHVVGrWQqGWVtXUACfQSSW
Ugk9ha5fzg+MPticFko8thg=
=hrfX
-----END PGP SIGNATURE-----