Today's kernel vulnerability announcement

"Keith Mastin" <[email protected]>
Newsgroups gmane.linux.redhat.release.valhalla,gmane.linux.redhat.release.enigma
Message-ID <[email protected]>
Just a heads up to everyone about the kernel vulnerability announcement
sent out by redhat.
https://rhn.redhat.com/network/errata/errata_details.pxt?eid=1540

I took a look into the matter before upgrading, as IMHO upgrading the
kernel is serious and shouldn't be done unless necessary. I've had
experience with installing "upgraded" kernels that have presented far more
problems than they've solved.

The announcement was made as a result of Alan Cox's disclosure to
vulnerability watch. Alan's vulnerability disclosure is directed toward
kernel 2.2.25, although it also affects 2.4 kernels before 2.4.20. You can
see Alan's disclosure here:
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html

The bottom line is that the vulnerability allows local users to gain root
access to the system. There is no possibility of using the vulnerability
to gain remote root access to the system. Single user systems and systems
where the users are not allowed shell access are not vulnerable.

I would suggest that you look into this further before upgrading.

Regards,
-- 
Keith Mastin
BeechTree Information Technology Services Inc.
Toronto, Canada
(416)696 6070
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.