1 |
On Wed, Feb 18, 2004 at 04:57:23PM +0100, Christian Gut wrote: |
2 |
> damn, again: |
3 |
> |
4 |
> http://bugs.gentoo.org/show_bug.cgi?id=42031 |
5 |
> http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt |
6 |
|
7 |
It looks like there is a discrepancy between the isec.pl link and the |
8 |
original bugtraq post by Paul Starzetz. The bugtraq post says: |
9 |
|
10 |
"Tested and known to be vulnerable kernel versions are all <= 2.2.25, <= |
11 |
2.4.24 and <= 2.6.1. The 2.2.25 version of Linux kernel does not |
12 |
^^^^^ |
13 |
recognize the MREMAP_FIXED flag but this does not prevent the bug from |
14 |
being successfully exploited. All users are encouraged to patch all |
15 |
vulnerable systems as soon as appropriate vendor patches are released. |
16 |
There is no hotfix for this vulnerablity. Limited per user virtual |
17 |
memory still permits do_munmap() to fail." |
18 |
|
19 |
Link: |
20 |
http://securityfocus.com/archive/1/354284/2004-02-15/2004-02-21/0 |
21 |
|
22 |
The isec.pl link has the same paragraph except that it's noted as |
23 |
<= 2.6.2 instead of 2.6.1. Anyone know what is going on here? I don't |
24 |
mind updating my kernel and rebooting, but if I'd like to make sure I'm |
25 |
doing it for a good reason :) |
26 |
|
27 |
Alan |
28 |
-- |
29 |
Alan <alan@×××××.org> - http://arcterex.net |
30 |
-------------------------------------------------------------------- |
31 |
"There are only 3 real sports: bull-fighting, car racing and mountain |
32 |
climbing. All the others are mere games." -- Hemingway |
33 |
|
34 |
-- |
35 |
gentoo-dev@g.o mailing list |