From mboxrd@z Thu Jan 1 00:00:00 1970 Date: Thu, 08 Jun 2000 18:55:27 -0400 From: sat To: linuxppc-dev@lists.linuxppc.org Subject: GeeK: more proof... Message-ID: <2712820046.960490527@[192.168.0.69]> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Sender: owner-linuxppc-dev@lists.linuxppc.org List-Id: Can I apply the standard patch from 2.2.15 to 2.2.16 in Paul's CVS kernel? ---------- Forwarded Message ---------- Date: Thursday, June 08, 2000 1:23 AM -0400 From: Dug Song To: backrow@citi.umich.edu Subject: GeeK: more proof... this is amazingly bad. http://sendmail.net/?feed=000607linuxbug A serious bug has been discovered in the Linux kernel that can be used by local users to gain root access. The problem, a vulnerability in the Linux kernel capability model, exists in kernel versions up to and including version 2.2.15. According to Alan Cox, a key member of the Linux developer community, "It will affect programs that drop setuid state and rely on losing saved setuid, even those that check that the setuid call succeeded." -d. --- http://www.monkey.org/~dugsong/ ---------- End Forwarded Message ---------- ** Sent via the linuxppc-dev mail list. See http://lists.linuxppc.org/