Un mail d'Alan Cox : De: Alan Cox
On Fri, Jan 07, 2005 at 05:43:29PM -0500, Will Backman wrote:
> Anyone tried the recently announced local root exploits against Fedora
> Core? Do the stack protections and other stuff protect the Fedora
> Kernel?
Not in this case
> I've manage a university shell server with many many student accounts.
> Scared....
Its fixed in 2.6.10-ac6 along with the following
- DoS/oops in setsid (user triggerable) <==
- Coda unverified user data (only if using Coda)
- XFS unverified user data (only if using XFS)
- Bridge ioctl (only if using bridge and already net_admin)
- Rose ioctl (only if using rose and already net_admin)
- SDLA firmware ioctls (only if net_admin and using sdla)
Donc c'est déjà fixé dans la branche Alan Cox (mais ce n'est pas le même patch) depuis ac6 (le ac8 est sorti il y a 2 jours).
On aurait pu passer 6 news en première page de plus et en une semaine seulement.
Dans Fedora il n'y a pas BINFMT_AOUT de compilé donc il n'y a pas de risque. Je pense que beaucoup de distributions font de même.
[^] # Re: Bugs et noyau
Posté par morgendorffer . En réponse à la dépêche Nouvelle faille dans les noyaux 2.4 et 2.6. Évalué à 2.
De: Alan Cox
On Fri, Jan 07, 2005 at 05:43:29PM -0500, Will Backman wrote:
> Anyone tried the recently announced local root exploits against Fedora
> Core? Do the stack protections and other stuff protect the Fedora
> Kernel?
Not in this case
> I've manage a university shell server with many many student accounts.
> Scared....
Its fixed in 2.6.10-ac6 along with the following
- DoS/oops in setsid (user triggerable) <==
- Coda unverified user data (only if using Coda)
- XFS unverified user data (only if using XFS)
- Bridge ioctl (only if using bridge and already net_admin)
- Rose ioctl (only if using rose and already net_admin)
- SDLA firmware ioctls (only if net_admin and using sdla)
Donc c'est déjà fixé dans la branche Alan Cox (mais ce n'est pas le même patch) depuis ac6 (le ac8 est sorti il y a 2 jours).
On aurait pu passer 6 news en première page de plus et en une semaine seulement.
Dans Fedora il n'y a pas BINFMT_AOUT de compilé donc il n'y a pas de risque. Je pense que beaucoup de distributions font de même.