Games | Software 
Search

Home|Channels|Hot news|Most visited|Highest rated|
Technology index
Hardware
Interviews
IT Companies
Security
Tech Weblogs
Technology
Set this page as your
home page
Add this page to your
favorites

Home Technology SlashDot IT

Bug In Most Linuxes Can Give Untrusted Users Root
November 4, 2009, 5:00 pm


Red Midnight and other readers brought to our attention a bug in most deployed versions of Linux that could result in untrusted users getting root access. The bug was found by Brad Spengler last month. "The null pointer dereference flaw was only fixed in the upcoming 2.6.32 release candidate of the Linux kernel, making virtually all production versions in use at the moment vulnerable. While attacks can be prevented by implementing a common feature known as mmap_min_addr, the RHEL distribution... doesn't properly implement that protection... The... bug is mitigated by default on most Linux distributions, thanks to their correct implementation of the mmap_min_addr feature. ... [Spengler] said many other Linux users are also vulnerable because they run older versions or are forced to turn off [mmap_min_addr] to run certain types of applications." The register reprints a dialog from the OpenBSD-misc mailing list in which Theo De Raadt says, "For the record, this particular problem was resolved in OpenBSD a while back, in 2008. We are not super proud of the solution, but it is what seems best faced with a stupid Intel architectural choice. However, it seems that everyone else is slowly coming around to the same solution."

Read more of this story at Slashdot.


Read more...
E-mailE-mail  Printer friendlyPrinter friendly version


Rate this article: 1 2 3 4 5  

Related stories...
Tech Lobbyist Named to DHS Top Security Post
Zero-Day IE Exploit In the Wild
Top Five Causes of Data Compromise
Pipeline Worm Floods AIM With Botnet Drones
Hotel Minibar Key Opens Diebold Voting Machines
The Engine of US Jobs
Draft Scheme Standard R6RS Released
CryptoDox: Encyclopedia on Cryptography & Info
Analyzing 20,000 MySpace Passwords
Code Posted For New IE Exploit
Powered by Apache, PHP, MySQL © 2006 Elerion, ltd.