发新话题
打印

[转载]Patching CVE-2008-0600, Local Root Exploit

本主题由 pub!1c 于 2008-2-21 00:45 加入精华

[转载]Patching CVE-2008-0600, Local Root Exploit

信息来源:邪恶八进制信息安全团队(www.eviloctal.com

> There is a security hole "splice: missing user pointer access verification
> (CVE-2008-0009/10)"  (exploit exist as proof of concept) for all kernels
> between 2.6.12-2.6.24.1 (included) which allows any user get root access
> --

vmsplice() has cause several vulnerabilities recently, and it's
trivial to exploit:

http://forum.eviloctal.com/thread-32206-1-1.html

There are patches and updated kernel packages appearing for the various *nixs:

http://kerneltrap.org/Linux/Patc ... _Local_Root_Exploit

TOP

TOP

发新话题