Re: another kernel vulnerability

2004-01-06 Thread Jose Luis Domingo Lopez
On Monday, 05 January 2004, at 17:21:52 +0100, Teófilo Ruiz Suárez wrote: > What about 2.6? Is it fixed anyhow? > It seems to be fixed in 2.6.1-rc2, as Linus said. But the fix seems to be temporary while kernel gurus and the people in charge of libc agree on a better solution. http://marc.theaims

Re: another kernel vulnerability

2004-01-06 Thread Jose Luis Domingo Lopez
On Monday, 05 January 2004, at 17:21:52 +0100, Teófilo Ruiz Suárez wrote: > What about 2.6? Is it fixed anyhow? > It seems to be fixed in 2.6.1-rc2, as Linus said. But the fix seems to be temporary while kernel gurus and the people in charge of libc agree on a better solution. http://marc.theaims

Re: another kernel vulnerability

2004-01-05 Thread Andreas Barth
* Thomas Sjögren ([EMAIL PROTECTED]) [040105 16:10]: > If you haven't heard it already: > Synopsis: Linux kernel do_mremap local privilege escalation > vulnerability > Product: Linux kernel > Version: 2.2, 2.4 and 2.6 series > http://isec.pl/vulnerabilities/isec-0013-mremap.txt > > Patch: > h

Re: another kernel vulnerability

2004-01-05 Thread Andreas Barth
* Thomas Sjögren ([EMAIL PROTECTED]) [040105 16:10]: > If you haven't heard it already: > Synopsis: Linux kernel do_mremap local privilege escalation > vulnerability > Product: Linux kernel > Version: 2.2, 2.4 and 2.6 series > http://isec.pl/vulnerabilities/isec-0013-mremap.txt > > Patch: > h

Re: another kernel vulnerability

2004-01-05 Thread Kjetil Kjernsmo
On Monday 05 January 2004 16:38, Thijs Welman wrote: > This issue has been fixed in the 2.4.24 version (2004-01-05 13:55 > UTC) > > Changelog: > http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24 Yeah, it seems Marcello released this to specifically address this issue. Perhaps he has ad

Re: another kernel vulnerability

2004-01-05 Thread Teófilo Ruiz Suárez
El lun, 05-01-2004 a las 16:38, Thijs Welman escribió: > Hi, > > Ricardo Kustner wrote: > > > Yeah I just finished updating my first server of many ;-) > > BTW even though not all mirrors are updated yet, you can get a patch from > > www.kernel.org -- that would probably be a better place to get

Re: another kernel vulnerability

2004-01-05 Thread Thijs Welman
Hi, Ricardo Kustner wrote: Yeah I just finished updating my first server of many ;-) BTW even though not all mirrors are updated yet, you can get a patch from www.kernel.org -- that would probably be a better place to get the patch from. This issue has been fixed in the 2.4.24 version (2004

Re: another kernel vulnerability

2004-01-05 Thread Kjetil Kjernsmo
On Monday 05 January 2004 16:38, Thijs Welman wrote: > This issue has been fixed in the 2.4.24 version (2004-01-05 13:55 > UTC) > > Changelog: > http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.24 Yeah, it seems Marcello released this to specifically address this issue. Perhaps he has ad

Re: another kernel vulnerability

2004-01-05 Thread Ricardo Kustner
On Monday 05 January 2004 15:50, Thomas Sjögren wrote: > If you haven't heard it already: > Synopsis: Linux kernel do_mremap local privilege escalation > vulnerability > Product: Linux kernel > Version: 2.2, 2.4 and 2.6 series > http://isec.pl/vulnerabilities/isec-0013-mremap.txt > http://linu

Re: another kernel vulnerability

2004-01-05 Thread Teófilo Ruiz Suárez
El lun, 05-01-2004 a las 16:38, Thijs Welman escribió: > Hi, > > Ricardo Kustner wrote: > > > Yeah I just finished updating my first server of many ;-) > > BTW even though not all mirrors are updated yet, you can get a patch from > > www.kernel.org -- that would probably be a better place to get

Re: another kernel vulnerability

2004-01-05 Thread Thijs Welman
Hi, Ricardo Kustner wrote: Yeah I just finished updating my first server of many ;-) BTW even though not all mirrors are updated yet, you can get a patch from www.kernel.org -- that would probably be a better place to get the patch from. This issue has been fixed in the 2.4.24 version (2004-01-

Re: another kernel vulnerability

2004-01-05 Thread Ricardo Kustner
On Monday 05 January 2004 15:50, Thomas Sjögren wrote: > If you haven't heard it already: > Synopsis: Linux kernel do_mremap local privilege escalation > vulnerability > Product: Linux kernel > Version: 2.2, 2.4 and 2.6 series > http://isec.pl/vulnerabilities/isec-0013-mremap.txt > http://linu