Click to See Complete Forum and Search --> : New Linux Exploit


Syngin
10-22-2001, 11:35 AM
I received an email from our server provider this morning and wanted to pass it on in case it hadn't been mentioned here yet (excerpt):

Recently, a new exploit was discovered for the Linux Kernel.
This exploit allows a user who has a shell account on your
machine to gain root level access. Currently, this exploit
is not able to be used remotely, but this exploit could be
used in conjunction with other exploits that give users
shell access to your machine to elevate their privileges to
that of root.

This exploit affects kernel versions 2.2.19-6.2.1 and
lower, as well as kernel versions 2.4.10 and lower.


Unfortunately, they're a little vague in their description of the exploit so, if anyone comes across the particulars, I'd love to hear about them.

Our server provider has a cluster of 2300 servers (90% of which are Linux based) so they are usually very on top of things like this.

Dark Ninja
10-22-2001, 12:05 PM
Yes...I believe this is what you are talking about. You can find the informationo at the following link, courtesy of SecurityFocus.com and BugTraq. (Please note: Being able to understand programming code makes this a lot easier to read.)

BugTraq - Recent Linux Kernel Exploits (http://www.securityfocus.com/archive/1/221337)


Dark Ninja

P.S. Please note - upgrading to 2.4.12 should fix both problems with the Linux kernel.

[ 22 October 2001: Message edited by: Dark Ninja ]

Syngin
10-22-2001, 12:08 PM
Thanks. I'll give that URL a peek. :)