Pour ceux qui doutent dans les 15 derniers jours :
FreeBSD : possibilité de modifier les tables de routage depuis une jail()
NetBSD : There exists a integer handling vulnerability in NetBSD swapctl(2) system call. It seems that this vulnerability can not be exploited to gain super-user privilegies, but any local attacker can crash the kernel. The vulnerability has been discovered several months ago by Evgeny Demidov during NetBSD kernel source code au dit. It has been made availabe to VulnDisco clients two months ago.
IRIX : that under certain conditions non privileged users can use the syssgi system call SGI_IOPROBE to read and write kernel memory which can be used to obtain root user privileges.
Two local DoS fixes are also addressed in these patches
[^] # Re: Bravo linux ...
Posté par ckyl . En réponse au journal faille dans les linux 2.4.2x et 2.6.x. Évalué à 2.
FreeBSD : possibilité de modifier les tables de routage depuis une jail()
NetBSD : There exists a integer handling vulnerability in NetBSD swapctl(2) system call. It seems that this vulnerability can not be exploited to gain super-user privilegies, but any local attacker can crash the kernel. The vulnerability has been discovered several months ago by Evgeny Demidov during NetBSD kernel source code au dit. It has been made availabe to VulnDisco clients two months ago.
IRIX : that under certain conditions non privileged users can use the syssgi system call SGI_IOPROBE to read and write kernel memory which can be used to obtain root user privileges.
Two local DoS fixes are also addressed in these patches