[Security-Discuss] kernel update to fix sys_epoll_wait?

George Patterson <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Hello,

I'm just wondering if anyone is aware of an official kernel update 
for the SYS_EPoll_Wait Local Integer Overflow Vulnerability running
around? Its been verified 2.6.3-25mdk is exploitable and possible to
gain a root shell. 

I believe the issue has been corrected in the cookers
kernel-2.6.11.10mdk-1-1mdk, but I was hoping for a release not
considered to be in a development state.

Also, I've found numerous references to 
http://www.mandrivasecure.net/en/advisories/ while looking in to this, 
but the page comes up with a Forbidden message. 

Any information will be appreciated, and I apologize if this issue has
already been covered. Thanks.

references:

http://lists.grok.org.uk/pipermail/full-disclosure/2005-March/032314.html

fix: http://linux.bkbits.net:8080/linux-2.6/cset@422dd06a1p5PsyFhoGAJseinjEq3ew?nav=index.html|ChangeSet@-1d

The 'fix' link gives me a error, but I found a few patch references that
should work. I was hoping an official RPM would be released.

-- 
George Patterson
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.