Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Bug in latest Linux gives untrusted users root access
Search Topic:
Uniqs:
412
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Hacker Charged in $1M MAC Spoofing Biz »
« Am I judging this right?  
AuthorAll Replies

matunga

join:2003-07-26

 Bug in latest Linux gives untrusted users root access

A software developer has uncovered a bug in most versions of Linux that could allow untrusted users to gain complete control over the open-source operating system.

The null pointer dereference flaw was only fixed in the upcoming 2.6.32 release candidate of the Linux kernel, making virtually all production versions in use at the moment vulnerable.
»www.theregister.co.uk/2009/11/03···ability/


Drunkula
Premium
join:2000-06-12
Denton, TX
Well to Matunga's credit, at least he pointed out there is a fix this time.

KodiacZiller

join:2008-09-04
73368

Old news. There have been a couple of these NULL dereference bugs making noise on the Linux mailing lists for a while now. Since it has already been fixed by everyone, I fail to see why this is even news?

And the discoverer, Brad Spengler, while one of the best there is, also seems to have a major axe to grind with Linus. Perhaps it is because most of the kernel guys prefer SELinux over his GRsecurity?


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

said by KodiacZiller See Profile :

Old news. There have been a couple of these NULL dereference bugs making noise on the Linux mailing lists for a while now. Since it has already been fixed by everyone, I fail to see why this is even news?
Fixed by everyone, what does that mean? I mean while all the vendors might have it patched/fixed, it by no means indicates that all the users have updated etc. Often warnings aren't directed to the vendors themselves (they likely already know), but to their users so they know they need to update and even then they might not, but at least they have been told and their non-action is their choice (however sometimes they don't get to choose the consequences).

Blake
--
Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool

upb
Premium
join:2004-03-15
Carriere, MS
·AT&T Southeast

The workaround was published last August in the Slackware Security mailing list, but it applies to almost any distro. You simply make sure that you have a file named "/etc/sysctl.conf" which contains at least the following:


I've tested the exploit out against machines configured in that way, and the exploit has always failed.

SUMware
Premium
join:2002-05-21

reply to matunga
Re: Bug in latest Linux gives untrusted users root access

»www.theregister.co.uk/2009/11/03···ability/
quote:
The latest bug is mitigated by default on most Linux distributions, thanks to their correct implementation of the mmap_min_addr feature. But to make RHEL compatible with a larger body of applications, that distribution is vulnerable to attack even when the OS shows the feature is enabled, Spengler said.

A Red Hat spokeswoman said patches for the versions 4 and 5 of RHEL and MRG are available here. An update for RHEL 3 is in testing and should be released soon.


Cabal
Premium
join:2007-01-21
Boston, MA
reply to matunga
I don't have untrusted users.

KodiacZiller

join:2008-09-04
73368

reply to Link Logger
said by Link Logger See Profile :

said by KodiacZiller See Profile :

Old news. There have been a couple of these NULL dereference bugs making noise on the Linux mailing lists for a while now. Since it has already been fixed by everyone, I fail to see why this is even news?
Fixed by everyone, what does that mean? I mean while all the vendors might have it patched/fixed, it by no means indicates that all the users have updated etc. Often warnings aren't directed to the vendors themselves (they likely already know), but to their users so they know they need to update and even then they might not, but at least they have been told and their non-action is their choice (however sometimes they don't get to choose the consequences).

Blake
When I said "everyone" I meant all of the major distributions have already implemented work arounds (by adjusting the mmap_min_addr value in /proc). The only major distro not to fix it this way is Fedora (which is interesting since Fedora is usually one of the most security oriented distros).

As for alerting users, most users shouldn't have to worry about it, or if they do, the updates will be pushed automatically by most distros anyway.


Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
·Shaw

said by KodiacZiller See Profile :

As for alerting users, most users shouldn't have to worry about it, or if they do, the updates will be pushed automatically by most distros anyway.
Oh those evil automatic updates, funny how many people don't trust those. I believe in them, use them, but some people don't.

Blake
--
Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool
-
Forums » Up and Running » Security » SecurityHacker Charged in $1M MAC Spoofing Biz »
« Am I judging this right?  


Tuesday, 15-Dec 02:15:23 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [142] Verizon Kindly Forgives Kid's $21,917 3G Bandwidth Bill
· [103] Google To Sell Phone Directly To Consumers
· [72] TiVO Tries To Figure Out Where It Fits
· [55] Faster Verizon DSL Service Will Burn Your House Down
· [47] NY Times: AT&T 3G Network Is Secretly Awesome
· [29] Rural Broadband User? You're Screwed
· [26] Can Satire Take Down AT&T's 3G Network?
· [23] Sweden First To Get LTE Service
· [6] Monday Evening Links
· [1] Monday Morning Links
Most people now reading
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· Official Mediacom Email Discussion Thread [Mediacom]
· Lady Deathwhisper Strategy - 3.3 Live [World of Warcraft]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· personal check etiquette [General Questions]
· how to get money back when ripped off [General Questions]
· [ Classes] 3.3 Rogue [World of Warcraft]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]