republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Identity theft solutions: fraud alerts, credit monitoring.. »
« AVG pro 7.5 annoying pop-up till Decenber?  
AuthorAll Replies


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:

reply to oshooda
Re: Linux Kernel 2.6.22.16 and Prior Multiple Memory Corruption

said by oshooda See Profile :

Hmmm... I couldn't help but wonder when Ubuntu Gutsy will catch up.

me@cruncher:~$ uname -a
Linux cruncher 2.6.22-14-generic #1 SMP Tue Feb 12 07:42:25 UTC 2008 i686 GNU/Linux

I talked to one of our Security Team folks about this bug, and he says that he's aware of this and it's been scheduled for this week's security update to the kernel. They needed more time to test the fix for regressions than the other CVE's the last security release cycle.

(He also felt that the impact of this vulnerability is not particularly earth-shattering, as contrasted to, say, the vmsplice one)
--
Ubuntu MOTU Developer and Forums Council


sivran
God Save The Suite
Premium
join:2003-09-15
Arlington, TX
clubs:
·RoadRunner Cable

But, it appears to be a local 'sploit. Meaning, as long as only I have physical access to it, I'm not worried. Or did I miss something?

And my 2.4 deb box can continue chugging along, doing its duty quite efficiently.
--
Think outside the fox...Seamonkey


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:

said by sivran See Profile :

But, it appears to be a local 'sploit. Meaning, as long as only I have physical access to it, I'm not worried. Or did I miss something?

And my 2.4 deb box can continue chugging along, doing its duty quite efficiently.
Your Deb box actually had a DSA released to patch that up

And it's not even much of a root 'sploit locally -- it can only be triggered at all with certain modules actively loaded (the deprecated VIA southbridge OSS sound driver, some USB dongle gadget, one DRI module)
--
Ubuntu MOTU Developer and Forums Council

oshooda

join:2005-11-26

reply to jdong
Thanks for checking into that, and for the additional information.

I was pretty sure that this wasn't that much of an issue to begin with, but was a bit curious about why that kernel would still be in use if it were really as out of date as the first few posts might make it seem.


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:

said by oshooda See Profile :

Thanks for checking into that, and for the additional information.

I was pretty sure that this wasn't that much of an issue to begin with, but was a bit curious about why that kernel would still be in use if it were really as out of date as the first few posts might make it seem.
Well it always does take time for fixes to trickle down the stream so to speak. Distributions, vendors , and local administrators all tend to make decisions on whether or not to include certain patches, and whether to do so *NOW* or group a bunch together every month instead of spamming the user every other day.

From an upstream perspective this bug is an old news but certainly there might be downstream distributions that still employ a vulnerable kernel.
--
Ubuntu MOTU Developer and Forums Council
Forums » Up and Running » Security » SecurityIdentity theft solutions: fraud alerts, credit monitoring.. »
« AVG pro 7.5 annoying pop-up till Decenber?  


Friday, 09-Jan 03:33:56 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [162] New Comcast Throttling System 100% Online
· [112] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [112] iTunes Dumps The DRM
· [73] AT&T, Verizon Stocks Tumble
· [61] DOCSIS 3.0 Gets Faster
· [61] Taxing ISPs to Prop Up Failing Newspapers?
· [56] Cable To Grab 75% Of New Subs In 2009
· [55] Feds Start Wait List For DTV Converter Coupons
· [54] Rumor: Google Cooking Up Own Router
· [48] Verizon Again Tweaks DSL Bundles
Most people now reading
· How to download windows 7 beta [Microsoft help]
· [Beta] Windows 7 Beta will be available Friday Jan, 9 2009 [Microsoft help]
· Benchmarking WRT Firmware... Some Surprises! [Linksys]
· Is Blue-Ray here to stay? [General Questions]
· [WotLK] Hit Rating Cap - Hunters [World of Warcraft]
· Packet Loss / High Latency to WoW [Charter HSI/CATV]
· [ Professions] Northrend Herbalism and Mining Tracks [World of Warcraft]
· Archivis' Guide to Naxx (10-man) [World of Warcraft]
· What do you feel happens after someone dies? [General Questions]
· Airplane Cabin Pressurization [General Questions]