Gentoo Archives: gentoo-user

From: kashani <kashani-list@××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Cron and Local Root Vuln
Date: Thu, 13 Jul 2006 19:54:37
Message-Id: 44B69E21.4050707@badapple.net
In Reply to: [gentoo-user] Cron and Local Root Vuln by Ow Mun Heng
1 Ow Mun Heng wrote:
2 > There was a disclosure in bugtraq/full-disclosure on this issue.
3 > Main thread is here
4 > http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047831.html
5 >
6 > Workround is here
7 > http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047868.html
8 >
9 > Proof of concept is here
10 > http://www.milw0rm.com/exploits/2006
11 >
12 > This is on a GentooLInux Box 2.6.16-suspend2-r1 kernel.
13 >
14
15 updating to gentoo sources 2.6.16-r12 (2.6.16.24) or 2.6.17-r2
16 (2.6.17.4) also fixes it. genpatch-2.6.16-14 is the important file if
17 you're using other sources and the ebuild for
18 suspend2-sources-2.6.16-r11 includes it.
19
20 kashani
21 --
22 gentoo-user@g.o mailing list