Bug#378324: local root hole (race condition in /proc)

2006-07-15 Thread Florian Weimer
* Robert Millan: > The linux-2.6 packages in unstable are not affected (since they > don't include a.out support). That's not correct, the vulnerability is present even if a.out support is disabled. It's only one published exploit that requires a.out support. -- To UNSUBSCRIBE, email to [EMAI

Bug#378324: local root hole (race condition in /proc)

2006-07-15 Thread Robert Millan
Package: kernel-image-2.6.8-3-686 Version: 2.6.8-16sarge3 Severity: critical Tags: security See: http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047907.html Workaround is simple: mount /proc as nosuid The linux-2.6 packages in unstable are not affected (since they don't include a.ou