Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-02 Thread Christian Horchert
Am 02.12.2003 um 02:52 schrieb peace bwitchu: Will 2.4.20 Source be patched for the latest kernel local root vulnerability? On SuSE-Security Roman Drahtmüller has posted a workaround which may help as long as there is no patch (haven't try this one on my own). ###

Re: (php?) bug exploit report

2004-01-25 Thread Christian Horchert
On 20.01.2004, at 10:31, Chris Morris wrote: Safe mode would certainly have reduced the impact from that script, and I'd definitely recommend turning it on unless you're very confident of the quality of all your scripts. There's also: - register_globals off (its on by default PHP < 4.2, like in

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-02 Thread Christian Horchert
Am 02.12.2003 um 02:52 schrieb peace bwitchu: Will 2.4.20 Source be patched for the latest kernel local root vulnerability? On SuSE-Security Roman Drahtmüller has posted a workaround which may help as long as there is no patch (haven't try this one on my own). #

Re: (php?) bug exploit report

2004-01-25 Thread Christian Horchert
On 20.01.2004, at 10:31, Chris Morris wrote: Safe mode would certainly have reduced the impact from that script, and I'd definitely recommend turning it on unless you're very confident of the quality of all your scripts. There's also: - register_globals off (its on by default PHP < 4.2, like in woo