Hole In Linux Kernel Provides Root Rights 274
oztiks writes with this excerpt from The H:
"A vulnerability in the 32-bit compatibility mode of the current Linux kernel (and previous versions) for 64-bit systems can be exploited to escalate privileges. For instance, attackers can break into a system and exploit a hole in the web server to get complete root (also known as superuser) rights or permissions for a victim's system. According to a report, the problem occurs because the 32-bit call emulation layer does not check whether the call is truly in the Syscall table. Ben Hawkes, who discovered the problem, says the vulnerability can be exploited to execute arbitrary code with kernel rights. ... Hawkes says the vulnerability was discovered and remedied back in 2007, but at some point in 2008 kernel developers apparently removed the patch, reintroducing the vulnerability. The older exploit apparently only needed slight modifications to work with the new hole."
Serve them right (Score:5, Funny)
Patch (Score:5, Funny)
For those who compile from source, here is the patch:
---kernel.c
+++kernel.c
@@ -1,1 +1,1 @@
- void goatse(long cx) {
+ void goatse(int cx) {
The change from long to int closes the massive hole.
Re:Serve them right (Score:1, Funny)
Yes, LUNIX.
Re:Doesn't work (Score:3, Funny)
You are too stupid to live....
I guess for people like you, next time I need to add...
*** BEGIN JOKE ***
and
*** END JOKE ***
If that's still not enough - I can incorporate the blink tag and some colored fonts.
Re:Serve them right (Score:5, Funny)
I thought that was because you were a pretentious wanker?
Error in title (Score:5, Funny)
Patch (Score:4, Funny)
You can get a patch here [microsoft.com].
Re:Doesn't work (Score:4, Funny)
Re:Perhap the kernel's size is becoming too unweil (Score:5, Funny)
Re:Perhap the kernel's size is becoming too unweil (Score:1, Funny)
The fix was out before the maintainers rolled it back, too. Whoops.
Re:Serve them right (Score:5, Funny)
Thank you Adobe! you saved my machine!
Re:Perhap the kernel's size is becoming too unweil (Score:3, Funny)
Not interesting enough. Rewriting something that already works is where it's at.
Re:Patch (Score:1, Funny)
Re:Serve them right (Score:5, Funny)
And those even more in the know use a two-bit operating system like Windows :)
Re:exploited (Score:4, Funny)
Classy.
Re:Let's pretend Slashdotters are clueless (Score:2, Funny)
Re:Serve them right (Score:5, Funny)
1 bit operating systems are totally impossible to infect though.
That's true!
... Or false...
Re:exploited (Score:3, Funny)
You should have included the next two as well:
A Windows-specific character set and a looping nonexistent background sound. Heh.
Re:In Soviet Russia! (Score:1, Funny)
I'm sorry, but as a Linux guy, it's really hard to watch a Windows guy get a chuckle at somebody else given their chosen OS's inferiority and not have a chuckle about it myself.
As a BSD guy, it's really hard to watch a Linux guy get a chuckle at somebody else given their chosen OS's inferiority and not have a chuckle about it myself.