Re: exploit in linux kernel
Stefan Krah <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Linux From Scratch |
| Message-ID | <[email protected]> |
* Sam Halliday <[email protected]> wrote: > Dan Osterrath wrote: >> Sorry, but only in german... >> http://www.heise.de/newsticker/data/pab-25.10.02-001 > i have checked the kernel mailing list and cannot see this mentioned > amoung the developers.... err, coudl somebody please translate for me? > (i am in europe) I'll try a brief summary: CERT Stuttgart issued a warning about a local root exploit in all kernel versions < 2.2.22 or < 2.4.20. Some of the issues have been fixed in 2.4.19, but 2.4.19 still requires a patch available at http://thefreeworld.net/ . Look for the file named "kernel-2.4.19-sec". Before downloading the file, you must declare that you are neither a US citizen nor under US jurisdiction. The reasons for this policy are explained on the page. Another hint is to be found in Alan Cox' diary http://www.linux.org.uk/diary/ -> August 6th CERT Stuttgart points out that stealthy fixes and late announcements of kernel security issues are occurring almost on a regular basis now and they advise to use the latest kernel versions. Stefan Krah -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message