Re: Kernel exploit



Kevin Miller wrote:
LSMFT wrote:
Attackers have used a freely available exploit to target a number of
64-bit Linux machines, according to a Linux patch management software firm.

The exploit is particularly pernicious, as it can leave a backdoor on
systems that have workarounds deployed, according to rebootless Linux
security update company Ksplice. The stack pointer underflow weakness
has been given a common vulnerability code of CVE-2010-3081.

A new kernel just came down the pike a few days ago. Does it not patch
this exploit?

No. According to the security summary report posted yesterday to the
opensuse-security-announce list, a fix for this is being prepared.


2) Pending Vulnerabilities, Solutions, and Work-Arounds

- kernel
Vulnerabilities in the kernel were found that allow local users to
gain root privileges on 64bit systems. Updates for all supported
distributions are in the works (CVE-2010-3301, CVE-2010-3081).




--

Ulick Magee

Free software and free formats for free information for free people.
Open Office for Windows/OSX/Linux: http://www.openoffice.org
openSUSE Linux: http://en.opensuse.org
.



Relevant Pages

  • Re: Kernel exploit
    ... of 64-bit Linux machines, according to a Linux patch management ... A new kernel just came down the pike a few days ago. ... Pending Vulnerabilities, Solutions, and Work-Arounds ...
    (alt.os.linux.suse)
  • Kernel exploit
    ... Attackers have used a freely available exploit to target a number of 64-bit Linux machines, according to a Linux patch management software firm. ...
    (alt.os.linux.suse)
  • Re: Kernel exploit
    ... 64-bit Linux machines, according to a Linux patch management software ... firm. ... as it can leave a backdoor on ...
    (alt.os.linux.suse)
  • Re: differences between kernel-tree and kernel-source and kernel image
    ... > will this install the kernel or try to patch an existing 2.6 kernel or ... affix-source - Driver source for the Affix Bluetooth protocol stack for Linux ... atlas-doc - Automatically Tuned Linear Algebra Software,documentation ...
    (Debian-User)
  • LTTng finds abnormally long APIC interrupt handler : 58.2 ms
    ... A trace taken with LTTng on a x86_64 dual quad-core, Linux kernel ... # Input Device Drivers ...
    (Linux-Kernel)