* GeeK: more proof...
@ 2000-06-08 22:55 sat
0 siblings, 0 replies; only message in thread
From: sat @ 2000-06-08 22:55 UTC (permalink / raw)
To: linuxppc-dev
Can I apply the standard patch from 2.2.15 to 2.2.16 in Paul's CVS kernel?
---------- Forwarded Message ----------
Date: Thursday, June 08, 2000 1:23 AM -0400
From: Dug Song <dugsong@monkey.org>
To: backrow@citi.umich.edu
Subject: GeeK: more proof...
this is amazingly bad.
http://sendmail.net/?feed=000607linuxbug
A serious bug has been discovered in the Linux kernel that can be used
by local users to gain root access. The problem, a vulnerability in
the Linux kernel capability model, exists in kernel versions up to and
including version 2.2.15. According to Alan Cox, a key member of the
Linux developer community, "It will affect programs that drop setuid
state and rely on losing saved setuid, even those that check that the
setuid call succeeded."
-d.
---
http://www.monkey.org/~dugsong/
---------- End Forwarded Message ----------
** Sent via the linuxppc-dev mail list. See http://lists.linuxppc.org/
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2000-06-08 22:55 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2000-06-08 22:55 GeeK: more proof sat
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).