public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] Cron and Local Root Vuln
@ 2006-07-13 16:31 Ow Mun Heng
  2006-07-13 19:25 ` kashani
  0 siblings, 1 reply; 2+ messages in thread
From: Ow Mun Heng @ 2006-07-13 16:31 UTC (permalink / raw
  To: gentoo

There was a disclosure in bugtraq/full-disclosure on this issue.
Main thread is here
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047831.html

Workround is here
http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047868.html

Proof of concept is here
http://www.milw0rm.com/exploits/2006

This is on a GentooLInux Box 2.6.16-suspend2-r1 kernel.

-- 
Ow Mun Heng <Ow.Mun.Heng@wdc.com>

-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [gentoo-user] Cron and Local Root Vuln
  2006-07-13 16:31 [gentoo-user] Cron and Local Root Vuln Ow Mun Heng
@ 2006-07-13 19:25 ` kashani
  0 siblings, 0 replies; 2+ messages in thread
From: kashani @ 2006-07-13 19:25 UTC (permalink / raw
  To: gentoo-user

Ow Mun Heng wrote:
> There was a disclosure in bugtraq/full-disclosure on this issue.
> Main thread is here
> http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047831.html
> 
> Workround is here
> http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047868.html
> 
> Proof of concept is here
> http://www.milw0rm.com/exploits/2006
> 
> This is on a GentooLInux Box 2.6.16-suspend2-r1 kernel.
> 

updating to gentoo sources 2.6.16-r12 (2.6.16.24) or 2.6.17-r2 
(2.6.17.4) also fixes it. genpatch-2.6.16-14 is the important file if 
you're using other sources and the ebuild for 
suspend2-sources-2.6.16-r11 includes it.

kashani
-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-07-13 19:54 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-07-13 16:31 [gentoo-user] Cron and Local Root Vuln Ow Mun Heng
2006-07-13 19:25 ` kashani

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox