Page 3 of 11 FirstFirst 12345 ... LastLast
Results 21 to 30 of 107

Thread: 8-year-old kernel security hole found

  1. #21
    Join Date
    Nov 2005
    Location
    Sendai, Japan
    Beans
    11,296
    Distro
    Kubuntu

    Re: Another Critical Kernel Exploit Just Discovered

    There's already a thread on this topic, and besides, this is a support forum.

    Threads merged.
    「明後日の夕方には帰ってるからね。」


  2. #22
    Join Date
    Dec 2005
    Location
    Australia
    Beans
    7

    Re: 8-year-old kernel security hole found

    So what's being done about this, I dont mean to be arrogant at all, but I read about the Exploit @ the groovy "MVP hangout", calendar of Updateshttp://www.calendarofupdates.com/upd...howtopic=22012
    Obviously the point must be made that this vulnerability has existed for eight years and has only just been let out of the bag.
    Most importantly I can't fix this, anyone working on it

  3. #23
    Join Date
    Nov 2005
    Location
    Sendai, Japan
    Beans
    11,296
    Distro
    Kubuntu

    Re: 8-year-old kernel security hole found

    Quote Originally Posted by Uluru View Post
    So what's being done about this, I dont mean to be arrogant at all, but I read about the Exploit @ the groovy "MVP hangout", calendar of Updateshttp://www.calendarofupdates.com/upd...howtopic=22012
    Obviously the point must be made that this vulnerability has existed for eight years and has only just been let out of the bag.
    Most importantly I can't fix this, anyone working on it
    You can expect a fix to appear in the Ubuntu repos in the coming hours. Unlike other distros, Ubuntu has alway been quick to fix that sort of thigs, you gotta at least admit that.
    「明後日の夕方には帰ってるからね。」


  4. #24
    Join Date
    Jan 2007
    Beans
    Hidden!

    Re: 8-year-old kernel security hole found

    Quote Originally Posted by HymnToLife View Post
    You can expect a fix to appear in the Ubuntu repos in the coming hours. Unlike other distros, Ubuntu has alway been quick to fix that sort of thigs, you gotta at least admit that.
    One of the most important aspects that makes me stick to Ubuntu for good.

  5. #25
    Join Date
    Dec 2005
    Location
    Australia
    Beans
    7

    Re: 8-year-old kernel security hole found

    You can expect a fix to appear in the Ubuntu repos in the coming hours. Unlike other distros, Ubuntu has alway been quick to fix that sort of thigs, you gotta at least admit that.
    Now everyone knows about this I'm sure it'll be patched very quickly, and as you say available in the Repos. I just hate to see the hopelessly incompetent MS MVP's giggling at a Linux exploit
    Surprised they have time to pull themselves away from their Malware cleaning to even notice what's going on in the "Real World".
    No offence intended, even if it has to be implied

  6. #26
    Join Date
    Mar 2007
    Beans
    Hidden!

    Where is the update?

    Anyone have any idea when an updated kernel might become available? I have searched far and wide and cannot even find a bug report on it, searching for CVE-2009-2692.

    And FYI, the bug is not because some developer's bad coding. From my limited understanding of the kernel coding voodoo, the null pointers were accounted for. It is gcc compiler optimization that removed the checks after compiling the kernel. Source code looked fine, the bug only shows up in the finished product. The kernel code monkies are damn good, but I don't think they have jedi abilities like diff'ing source and binary code
    Last edited by Bad Penguin; August 14th, 2009 at 03:37 PM. Reason: CVE-2009-2692, not 1897

  7. #27
    Join Date
    Feb 2007
    Location
    Wolverhampton, UK
    Beans
    280
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: 8-year-old kernel security hole found

    Well, at least it looks good if Ubuntu get it patched nice and quickly!!


  8. #28
    Join Date
    Mar 2007
    Beans
    Hidden!

    Re: 8-year-old kernel security hole found

    Quote Originally Posted by Steve H View Post
    Well, at least it looks good if Ubuntu get it patched nice and quickly!!

    It is not patched, at least in dapper server LTS. I just confirmed by running the exploit posted here:

    http://seclists.org/fulldisclosure/2009/Aug/0180.html

  9. #29
    Join Date
    Feb 2007
    Location
    Wolverhampton, UK
    Beans
    280
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: 8-year-old kernel security hole found

    Quote Originally Posted by Bad Penguin View Post
    It is not patched, at least in dapper server LTS. I just confirmed by running the exploit posted here:

    http://seclists.org/fulldisclosure/2009/Aug/0180.html
    I did say "IF" !!


  10. #30
    Join Date
    Dec 2007
    Location
    .
    Beans
    Hidden!
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: 8-year-old kernel security hole found

    Quote Originally Posted by samjh View Post
    Good thing they've found the error. Bad thing is this will give Linux's opponents ammunition about how using amateurs programmers and volunteers result in poor security, and how FOSS's community development model is not secure.
    Yes because getting commit access to the linux kernel source code is only slightly harder than editing wikipedia.

Page 3 of 11 FirstFirst 12345 ... LastLast

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •