New Linux Bit Torrents Available Here

Home  

 


  Create an account

Search


[x]  
 
 [x]
Categories Menu
· All Categories
· Commands
· Distro News
· General
· Link of the Week
· Linux Jobs
· Security
· Software
· Tips

 
Navigation
 
User Info
Welcome, Anonymous

Username:
Password:

(Register)

Membership:
Latest: hiobgiou
New Today: 0
New Yesterday: 0
Overall: 225

People Online:
Visitors: 6
Members: 0
Total: 6

 
hacker Beware
You have been warned!
We have caught 1478 shameful hackers.

NukeSentinel(tm) 2.5.14

 
Hot Downloads
 
  
Security: Serious Linux kernel bug allows root shell
Posted on Tuesday, February 12 @ 02:22:19 CST by maysvill

Linux Computer & Network Security

A serious bug in the linux kernel v 2.6.17 or newer that allows a local user or someone who has ssh access to obtain root priviledges. The bug is due to vmsplice() system call.

CVE-2008-0009

CVE-2008-0010

CVE-2008-0600

More information here: dsd's weblog

Also, you can have a look at the redhat / fedora bugzilla which has a working exploit code

If you are the only person who uses your linux computer (locally or remote) then you really have nothing to worry about.

Steps to Reproduce:
1. Download http://downloads.securityfocus.com/vulnerabilities/exploits/27704.c
2. cc -o exploit 27704.c
3. [as non-privileged user] ./exploit

Actual results:

Root shell


 
Related Websites

Related Links
· More about Linux Computer & Network Security
· News by maysvill


Most read story about Linux Computer & Network Security:
Secure Your Boot Loader


 
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


 
Options
 
Associated Topics

Commands You Should Know How to UseLinux Computer & Network SecuritySoftwareTips & Tricks

The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

 
All content Copyright 2000 - 2008, Maysville Linux Users Group unless otherwise credited.
All Rights Reserved!
The opinions expressed by visitors to this web site are their own and not necessarily the opinions of the MLUG!


Web site powered by PHP-Nuke Web site powered by PHP-Nuke-NIP-76.0

You can syndicate our news using the file backend.php or ultramode.txt