First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 209602
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 209460
Assigned To: Gentoo Linux bug wranglers <bug-wranglers@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Janusz <janusz@uni.opole.pl>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 209602 depends on: Show dependency tree
Bug 209602 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2008-02-10 21:00 0000
"There is a security hole in all versions of linux-2.6 distributed by
Debian, including Etch's kernel."

This is taken from above Debian bugzilla. I confirm it on:

- vanilla 2.6.24.1
- gentoo-sources 2.6.24

both on x86_64. I failed to confirm on vanilla 2.6.23.8 on i586.


Reproducible: Always

Steps to Reproduce:
1.use
2.the exploit
3. included in Debian report! If it disappears for some reasons I can send it
to you.

Actual Results:  
System took over by local user.

Expected Results:  
Total disaster. 

I'm waiting for a patch, any local user accounts should be disabled.

------- Comment #1 From Jakub Moc (RETIRED) 2008-02-10 21:02:23 0000 -------

*** This bug has been marked as a duplicate of bug 209460 ***

First Last Prev Next    No search results available      Search page      Enter new bug