Re: Upcoming 4.18s - SECURITY ISSUES
Marc-Christian Petersen <[email protected]> Mon, 17 Jan 2005 14:37:58 +0100
| Newsgroups | gmane.linux.wolk.devel |
|---|---|
| Organization | Working Overloaded Linux Kernel |
| Message-ID | <200501171437.59020@WOLK> |
On Friday 14 January 2005 14:06, Marc-Christian Petersen wrote: Hi Gary, > > Just saw CAN-2005-0001 > > (http://www.isec.pl/vulnerabilities/isec-0022-pagefault.txt) and it > > doesn't look like your changelog includes it. Does this bug exist in the > > current 2.4 wolk? > yeah, exists there but fixed in upcoming 4.18s. See the changelog on sf.net > I'll release it this weekend. Ok, wasn't able to do so, still have some things to finish. I just checked the exploit for this case and your machine(s) aren't vulnerable if you use GRsecurity's restricted /proc feature because /proc/cpuinfo is not readable but for root and maybe the group you choosed which is able to read stuff in /proc. ciao, Marc ------------------------------------------------------- The SF.Net email is sponsored by: Beat the post-holiday blues Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt _______________________________________________ WOLK - Working Overloaded Linux Kernel [email protected] https://lists.sourceforge.net/lists/listinfo/wolk-devel