Re: getting the running patch level

2012-08-10 Thread Matthew Seaman
On 09/08/2012 23:13, Glen Barber wrote: > On Thu, Aug 09, 2012 at 03:31:25PM -0600, Brett Glass wrote: >> > I realize that sysinstall is deprecated in favor of the new installer, but >> > the new installer doesn't have the ability to install binary packages. >> > Until and unless there's a convenie

RE: getting the running patch level

2012-08-10 Thread Roberto
So as far I understand, if the kernel is not updated by the update process, it is not possible to get via "uname" the currently patch level. I also read about put some syscall to return from the kernel the current patch level, but still this solution is "bound" to the kernel modification, which c

Re: [Full-disclosure] nvidia linux binary driver priv escalation exploit

2012-08-10 Thread Simon L. B. Nielsen
On Wed, Aug 8, 2012 at 1:38 PM, Wesley Shields wrote: > On Wed, Aug 08, 2012 at 10:34:06AM +, Alexey Dokuchaev wrote: >> On Mon, Aug 06, 2012 at 01:49:50PM +0200, Rainer Hurling wrote: >> > Am 06.08.2012 10:03 (UTC+1) schrieb Doug Barton: >> > >On 08/01/2012 05:09, Oliver Pinter wrote: >> > >>

Re: getting the running patch level

2012-08-10 Thread Simon L. B. Nielsen
On Fri, Aug 10, 2012 at 1:06 PM, Roberto wrote: > > So as far I understand, if the kernel is not updated by the update process, it > is not possible to get via "uname" the currently patch level. Correct. This has been discussed a number of time, but there are no nice and simple solution. There i

Re: [Full-disclosure] nvidia linux binary driver priv escalation exploit

2012-08-10 Thread Janne Snabb
On 08/10/2012 09:35 PM, Simon L. B. Nielsen wrote: [..] > On 08/01/2012 05:09, Oliver Pinter wrote: >> I found this today on FD: >> >> http://seclists.org/fulldisclosure/2012/Aug/4 [..] > Eh, why wouldn't a CVE name not be assigned? If none is we should ask > MITRE to assign one, bu

Re: getting the running patch level

2012-08-10 Thread Chris BeHanna
On Aug 10, 2012, at 09:40 , Simon L. B. Nielsen wrote: > On Fri, Aug 10, 2012 at 1:06 PM, Roberto wrote: >> >> So as far I understand, if the kernel is not updated by the update process, >> it >> is not possible to get via "uname" the currently patch level. > > Correct. > > This has been dis

Re: getting the running patch level

2012-08-10 Thread Janne Snabb
On 08/10/2012 11:55 PM, Chris BeHanna wrote: > Split off a version.ko and update that with each patch? There is often no need to reboot the machine unless the kernel is affected (just restart the affected daemons). Thus the information would not necessarily match the userland status. The use

Re: getting the running patch level

2012-08-10 Thread olli hauer
On 2012-08-10 16:40, Simon L. B. Nielsen wrote: > On Fri, Aug 10, 2012 at 1:06 PM, Roberto wrote: >> >> So as far I understand, if the kernel is not updated by the update process, >> it >> is not possible to get via "uname" the currently patch level. > > Correct. > > This has been discussed a n