[aklug] Linux kernel local vulnerability

From: Jenkinson, John P (SAIC) <John.Jenkinson@bp.com>
Date: Tue Feb 12 2008 - 23:11:42 AKST

 
sudo replacement?
 
http://it.slashdot.org/it/08/02/10/2011257.shtml
 
local exploit
fedora has patches already
for cited versions of 2.6 kernel

as the poster i too had good success with published exploits. the
working exploits use /dev/kmem which

might require a quick edit to /dev/mem on some distros. other slight
mods to get other distros.

BUT run the resulting a.out and you have a root prompt. kinda like sudo
but no configuration to provide

and no password. nasty

the fedora fix for yesterday was superceded today, no explanation as to
why.

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Tue Feb 12 23:12:30 2008

This archive was generated by hypermail 2.1.8 : Tue Feb 12 2008 - 23:12:30 AKST