• [^] # Re: Faille de sécurité critique dans le kernel (2.2, 2.4, 2.6 touché!)

    Posté par . En réponse au journal Faille de sécurité critique dans le kernel (2.2, 2.4, 2.6 touché!). Évalué à 4.

    BSD roxor, BSD roxor c'est vite dit.

    Prenons OpenBSD et sa dernière release 3.4 (donc seulement à partir du 1er novembre 2003) et que vois-je, entre autre :

    - It may be possible for a local user to overrun the stack (...)
    - The use of certain ASN.1 encodings or malformed public keys may allow an attacker to mount a denial of service attack against applications linked with ssl (...)
    - It is possible for a local user to cause a system panic by flooding it with spoofed ARP requests.
    - A user with write permission to httpd.conf or a .htaccess file can crash httpd(8) or potentially run arbitrary code as the user www (...)
    - It is possible for a local user to cause a system panic (...)
    - It is possible for a local user to cause a crash (...)
    - An improper bounds check makes it possible for a local user to cause a crash (...)

    Oui, je suis tombé dedans mais tanpis.