From: | kashani <kashani-list@××××××××.net> | ||
---|---|---|---|
To: | gentoo-user@l.g.o | ||
Subject: | Re: [gentoo-user] Cron and Local Root Vuln | ||
Date: | Thu, 13 Jul 2006 19:54:37 | ||
Message-Id: | 44B69E21.4050707@badapple.net | ||
In Reply to: | [gentoo-user] Cron and Local Root Vuln by Ow Mun Heng |
1 | Ow Mun Heng wrote: |
2 | > There was a disclosure in bugtraq/full-disclosure on this issue. |
3 | > Main thread is here |
4 | > http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047831.html |
5 | > |
6 | > Workround is here |
7 | > http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047868.html |
8 | > |
9 | > Proof of concept is here |
10 | > http://www.milw0rm.com/exploits/2006 |
11 | > |
12 | > This is on a GentooLInux Box 2.6.16-suspend2-r1 kernel. |
13 | > |
14 | |
15 | updating to gentoo sources 2.6.16-r12 (2.6.16.24) or 2.6.17-r2 |
16 | (2.6.17.4) also fixes it. genpatch-2.6.16-14 is the important file if |
17 | you're using other sources and the ebuild for |
18 | suspend2-sources-2.6.16-r11 includes it. |
19 | |
20 | kashani |
21 | -- |
22 | gentoo-user@g.o mailing list |