Gentoo Archives: gentoo-user

From: "Timothy A. Holmes" <tholmes@×××××××××.net>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Linux Kernel Warning
Date: Fri, 14 Jul 2006 21:16:06
Message-Id: 17CD9CE4C0FA574A8B29EF02D49B385D0F5646@srvexch-01.mcaschool.local
1 Hi Folks:
2
3 I received the following warning from SANS yesterday, and I need to know
4 how to appropriately respond:
5
6 http://www.isc.sans.org/diary.php?storyid=1482
7
8 To summarize the story at the above link, there appears to be a
9 vulnerability in the linux kernel, which when exploited, will allow a
10 user to gain root privileges.
11
12 Normally, I would simply upgrade to the latest kernel from portage, and
13 be done with it, however, here is the problem:
14
15 QUOTING SANS HERE:
16 "As all kernels 2.6.13 up to version 2.6.17.4 and 2.6.16 before
17 2.6.16.24 are affected, you should patch as soon as possible, even if
18 you don't allow any local users on your machines."
19
20 As of this morning, the latest Kernel version in portage is 2.6.16-r12.
21 It seems that there is a different versioning / naming scheme used but
22 im not sure. Can someone please let me know how to respond, or point me
23 to appropriate reading so I can protect myself.
24
25 Thanks
26
27 TIM
28
29 Timothy A. Holmes
30 IT Manager / Network Admin / Web Master / Computer Teacher
31
32 Medina Christian Academy
33 A Higher Standard...
34
35
36
37 --
38 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Linux Kernel Warning Richard Fish <bigfish@××××××××××.org>
Re: [gentoo-user] Linux Kernel Warning Raymond Lewis Rebbeck <dystopianray@×××××.com>
Re: [gentoo-user] Linux Kernel Warning Donnie Berkholz <dberkholz@g.o>
Re: [gentoo-user] Linux Kernel Warning Daniel Drake <dsd@g.o>