RE: CAN-2004-1137
"hilton de meillon" <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
Hi Ron & All, I am able to update my kernel manually. Another post suggested that the vulnerability was not fixed as such but that the kernel config was just modified accordingly. I just find it puzzling that other "vendors" provide patches but many do not. Traditionally I believe that the vendor should provide the patch/update but I guess that is not as clear cut as in the past. Having to recompile a kernel for Gentoo, Slackware, etc for all of my machines is going to be a pain. I guess this is why everyone just sticks to redhat. -----Original Message----- From: Ron [mailto:[email protected]] Sent: Saturday, 1 January 2005 7:25 AM To: hilton de meillon Subject: Re: CAN-2004-1137 Can't you update your kernel manually? http://www.kernel.org -- download 2.6.10, read the instructions, and compile :) hilton de meillon wrote: >Hi All, > >Can anyone tell me why not many distros have an update for the >CAN-2004-1137 (among other kernel vulnerabilities) yet ?. > >Ubuntu, Redhat, SuSe have updated kernels but pretty much all the rest >do not have an updated kernel for this issue. > >Secondly would 'iptables -A INPUT -p IGMP -j REJECT' protect my machine >from remote attacks ?. > >I tried this rule and then ran the proof of concept exploit from >http://www.securityfocus.com/bid/11917/solution/ and it still crashed >my >(slackware) machine. I am assuming that it connects over a unix socket >or exploits one of the non-networked vulnerabilities as according to >secfocus there are three actual vulnerabilities contained in this vulnerability. > >Lastly I would have to say that this is a bit of a shocker for the >linux community, this vulnerability could be used with devastating >effect, I am a bit disappointed with linux in this regard. > >Any comments appreciated. > >hilton > > > > > >