1 |
Hi Folks: |
2 |
|
3 |
I received the following warning from SANS yesterday, and I need to know |
4 |
how to appropriately respond: |
5 |
|
6 |
http://www.isc.sans.org/diary.php?storyid=1482 |
7 |
|
8 |
To summarize the story at the above link, there appears to be a |
9 |
vulnerability in the linux kernel, which when exploited, will allow a |
10 |
user to gain root privileges. |
11 |
|
12 |
Normally, I would simply upgrade to the latest kernel from portage, and |
13 |
be done with it, however, here is the problem: |
14 |
|
15 |
QUOTING SANS HERE: |
16 |
"As all kernels 2.6.13 up to version 2.6.17.4 and 2.6.16 before |
17 |
2.6.16.24 are affected, you should patch as soon as possible, even if |
18 |
you don't allow any local users on your machines." |
19 |
|
20 |
As of this morning, the latest Kernel version in portage is 2.6.16-r12. |
21 |
It seems that there is a different versioning / naming scheme used but |
22 |
im not sure. Can someone please let me know how to respond, or point me |
23 |
to appropriate reading so I can protect myself. |
24 |
|
25 |
Thanks |
26 |
|
27 |
TIM |
28 |
|
29 |
Timothy A. Holmes |
30 |
IT Manager / Network Admin / Web Master / Computer Teacher |
31 |
|
32 |
Medina Christian Academy |
33 |
A Higher Standard... |
34 |
|
35 |
|
36 |
|
37 |
-- |
38 |
gentoo-user@g.o mailing list |