Tavis Ormandy and Julien Ninnes have discovered a severe security flaw in all 2.4 and 2.6 kernals since 2001 on all architectures. 'Since it leads to the kernal executing code at NULL, the vulnerability is as trivial as it can get to exploit: an attacker can just put code in the first page that will get executed with kernal privelages.
Incorrect proto_ops initializations
RedHat official mitigation reccomendation: https://bugzilla.redhat.com/show_bug.cgi?id=516949#c10
--- Finish reading this story at the link below ---
Read this on TheTechForum at Local Privilege Escalation on all Linux Kernals
Thursday, 3 September 2009
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment