[NUGA] Linux kernel local vulnerability

From: Jenkinson, John P (SAIC) <John.Jenkinson@bp.com>
Date: Wed Feb 13 2008 - 07:25:01 AKST

 
sudo replacement?
 
http://it.slashdot.org/it/08/02/10/2011257.shtml
 
local exploit
fedora has patches already

for cited versions of 2.6 kernel

as the poster i too had good success with published exploits. the
working exploits use /dev/kmem which

might require a quick edit to /dev/mem on some distros. other slight
mods to get other distros.

BUT run the resulting a.out and you have a root prompt. kinda like sudo
but no configuration to provide

and no password. nasty

the fedora fix for yesterday was superceded today, no explanation as to
why.

 

 

 

ALSO

Adobe reader 8.1.2 fixes for exploits in the wild

http://isc.sans.org/diary.html?storyid=3958

---------
To unsubscribe, send email to <nuga-request@lib.uaa.alaska.edu>
with 'unsubscribe' in the message body. To manage your subscription,
follow the directions at https://www.lib.uaa.alaska.edu/cgi-bin/lists.cgi
Received on Wed Feb 13 07:28:22 2008

This archive was generated by hypermail 2.1.8 : Wed Feb 13 2008 - 07:28:35 AKST