Today's kernel vulnerability announcement
"Keith Mastin" <[email protected]>
| Newsgroups | gmane.linux.redhat.release.valhalla,gmane.linux.redhat.release.enigma |
|---|---|
| Message-ID | <[email protected]> |
Just a heads up to everyone about the kernel vulnerability announcement sent out by redhat. https://rhn.redhat.com/network/errata/errata_details.pxt?eid=1540 I took a look into the matter before upgrading, as IMHO upgrading the kernel is serious and shouldn't be done unless necessary. I've had experience with installing "upgraded" kernels that have presented far more problems than they've solved. The announcement was made as a result of Alan Cox's disclosure to vulnerability watch. Alan's vulnerability disclosure is directed toward kernel 2.2.25, although it also affects 2.4 kernels before 2.4.20. You can see Alan's disclosure here: http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0134.html The bottom line is that the vulnerability allows local users to gain root access to the system. There is no possibility of using the vulnerability to gain remote root access to the system. Single user systems and systems where the users are not allowed shell access are not vulnerable. I would suggest that you look into this further before upgrading. Regards, -- Keith Mastin BeechTree Information Technology Services Inc. Toronto, Canada (416)696 6070