Re: Serious local root exploit in linux kernel

2008-02-11 Thread Sarunas Burdulis
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 GaRaGeD Style wrote: > Any Idea on why it doesn't work on a 2.6.18-openvz-13-1etch5-686 kernel ? > > I tested 2 boxes and 2 variants of exploits, none worked. > > I will take care of the "normal" ones :) > > Max Doesn't work on Xen-modified kernels

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Vincent Lefevre
On 2008-02-11 14:26:59 +0100, Rorist wrote: > Just tried on 2.6.23-1-amd64 and it works. This is strange because here it doesn't work: vin:~tmp> uname -a Linux vin 2.6.23.13-ws-intel64-p4 #1 SMP PREEMPT Mon Jan 28 23:40:29 CET 2008 x86_64 GNU/Linux vin:~tmp> ./root_expl -

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Douglas A. Tutty
On Mon, Feb 11, 2008 at 10:52:57AM -0500, Kamaraju S Kusumanchi wrote: > I am wondering what would be a good way to keep abreast of these kind of > serious vulnerabilities. How did you come to know of this information? Is > there any mailing list that I could subscribe? or there is a better > alt

Re: Serious local root exploit in linux kernel

2008-02-11 Thread GaRaGeD Style
Any Idea on why it doesn't work on a 2.6.18-openvz-13-1etch5-686 kernel ? I tested 2 boxes and 2 variants of exploits, none worked. I will take care of the "normal" ones :) Max --

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Kamaraju S Kusumanchi
Raj Kiran Grandhi wrote: > Please see: > > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464945 > https://bugs.launchpad.net/ubuntu/+source/linux-source-2.6.22/+bug/190587 > https://bugzilla.redhat.com/show_bug.cgi?id=432229 > Scary, indeed! Thanks for informing. I am wondering what would b

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Kumar Appaiah
On Mon, Feb 11, 2008 at 07:08:17PM +0530, Kumar Appaiah wrote: > On Mon, Feb 11, 2008 at 02:07:41PM +0100, Vincent Lefevre wrote: > > > A local root exploit has been discovered in the linux kernel yesterday. > > > Virtually all the stock kernels provided by several distributions in the > > > pa

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Kumar Appaiah
On Mon, Feb 11, 2008 at 02:07:41PM +0100, Vincent Lefevre wrote: > > A local root exploit has been discovered in the linux kernel yesterday. > > Virtually all the stock kernels provided by several distributions in the > > past year appear to be vulnerable. > > Is it specific to x86 (not x86_64

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Rorist
Hello, Just tried on 2.6.23-1-amd64 and it works. > On Feb 11, 2008 2:07 PM, Vincent Lefevre <[EMAIL PROTECTED]> wrote: > > On 2008-02-11 07:17:08 +0530, Raj Kiran Grandhi wrote: > > > A local root exploit has been discovered in the linux kernel yesterday. > > > Virtually all the stock kernels p

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Rorist
Hello, Just tried on 2.6.23-1-amd64 and it works. On Feb 11, 2008 2:07 PM, Vincent Lefevre <[EMAIL PROTECTED]> wrote: > On 2008-02-11 07:17:08 +0530, Raj Kiran Grandhi wrote: > > A local root exploit has been discovered in the linux kernel yesterday. > > Virtually all the stock kernels provided

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Vincent Lefevre
On 2008-02-11 07:17:08 +0530, Raj Kiran Grandhi wrote: > A local root exploit has been discovered in the linux kernel yesterday. > Virtually all the stock kernels provided by several distributions in the > past year appear to be vulnerable. Is it specific to x86 (not x86_64) as the exploit con

Re: Serious local root exploit in linux kernel

2008-02-11 Thread Jaime Tarrant
Jeff D wrote: Raj Kiran Grandhi wrote: Please see: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464945 https://bugs.launchpad.net/ubuntu/+source/linux-source-2.6.22/+bug/190587 https://bugzilla.redhat.com/show_bug.cgi?id=432229 A local root exploit has been discovered in the linux kernel

Re: Serious local root exploit in linux kernel

2008-02-10 Thread Jeff D
Raj Kiran Grandhi wrote: Please see: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464945 https://bugs.launchpad.net/ubuntu/+source/linux-source-2.6.22/+bug/190587 https://bugzilla.redhat.com/show_bug.cgi?id=432229 A local root exploit has been discovered in the linux kernel yesterday. Virt

Re: Serious local root exploit in linux kernel

2008-02-10 Thread Raj Kiran Grandhi
Raj Kiran Grandhi wrote: Please see: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464945 https://bugs.launchpad.net/ubuntu/+source/linux-source-2.6.22/+bug/190587 https://bugzilla.redhat.com/show_bug.cgi?id=432229 A local root exploit has been discovered in the linux kernel yesterday. Virt

Serious local root exploit in linux kernel

2008-02-10 Thread Raj Kiran Grandhi
Please see: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=464945 https://bugs.launchpad.net/ubuntu/+source/linux-source-2.6.22/+bug/190587 https://bugzilla.redhat.com/show_bug.cgi?id=432229 A local root exploit has been discovered in the linux kernel yesterday. Virtually all the stock kernel