Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 14-02-2008, 07:33 AM   #1 (permalink)
Host4Cheap.org
 
Sukhdeep Singh's Avatar
 
Join Date: May 2005
Location: Digit Forum
Posts: 2,102
Default Major Linux security hole found


Quote:
Feb. 11, 2008

Security, the experts like to tell us, is a process, not a product.

With open source that can be a very good thing since when security problems are found they can be fixed quickly. That's the case over this last weekend, Feb. 9-10, when a security problem was found, and given a hot fix, in the 2.6.17 to the most recent production Linux kernel, 2.6.24.1.

The problem's exploit was first shown on the security site Milw0rm. The specific trouble is with the kernel system call sys_vmsplice.

This system call moves data from a user space memory address range via a pipe to another destination. Like its relations, splice, which reads and writes data to/from the buffer and tee, which is commonly used to display a program's output and sends it into a file, this is a data transfer system call. It is primarily used in virtual memory management. Thus, in and of itself, end-users will never directly encounter it.

However, thanks to the release of exploit code, a user with just a bit of knowledge on how to compile his or her own program in Linux will be able to exploit a server. The bug's effect is, in those versions of Linux using these kernels with this system call compiled in, to enable ordinary users with shell access to obtain root, superuser privileges. The security hole has been demonstrated in Debian, Fedora and Ubuntu.
Source : http://www.linux-watch.com/news/NS8844914464.html
__________________
★ Want to start your Website, No worries - here is how ★
http://www.thinkdigit.com/forum/showthread.php?t=66717

★ Host4Cheap - cPanel Webhosting & Reseller Plans ★
http://www.host4cheap.org/
Sukhdeep Singh is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 14-02-2008, 04:14 PM   #2 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Major Linux security hole found

LINUX HOLE PATCHED

Quote:
Not long after we reported that there was a major security hole in Linux, the Linux kernel developers came up with a permanent patch for the problem.

The security hole was with the relatively new Linux kernel system call sys_vmsplice. This system call moves data from a user space memory address range via a pipe to another destination. It's present in Linuxes using the Linux kernel from Version 2.6.17 to what had been the latest production Linux kernel, 2.6.24.1.

An exploit for this system call was revealed on the security exploit site Milw0rm on Feb. 9. This exploit showed that a user with local shell access and the exploit in hand could obtain root, master administration access to a Linux system.

A hot-fix was issued almost immediately. The permanent patch was delivered on the evening of Feb. 10. As Greg Kroah-Hartman, senior Linux developer employed by Novell, reported that night, "All currently active Linux kernel versions are now released with a fix for this problem. We have released them through our normal channels, with the needed information as to what the problem is, a pointer to the CVE number, and the patch itself."

There are two slightly different versions of the patch, depending on which Linux kernel you're running. But as master Linux developer Linus Torvalds wrote on the LKML (Linux Kernel Mailing List) concerning this, "In this particular case, maybe some [stable] person [a developer working on the stable, rather than experimental, versions of Linux] might have felt that they just didn't want to change semantics for the NULL pointer, or maybe they didn't even notice that what I committed to the development tree was slightly changed. It _really_ doesn't matter."

Updated versions of the kernel with the fix are now available for Debian, Ubuntu, openSUSE, Fedora, Red Hat and presumably all other mainstream Linuxes. Many of them, such as openSUSE, are automatically delivering the repaired Linux system.

—Steven J. Vaughan-Nichols

Do you have comments on this story?Talkback here
NOTE: Please post your comments regarding our articles using the above link. Be sure to use this article's title as the "Subject" in your posts. Before you create a new thread, please check to see if a discussion thread is already running on the article you plan to comment on. Thanks!

__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 14-02-2008, 05:45 PM   #3 (permalink)
 Macboy
 
goobimama's Avatar
 
Join Date: Sep 2004
Location: Goa
Posts: 4,486
Default Re: Major Linux security hole found

^^ Ah the power of Opensource
__________________
I'm like a bird... :)
goobimama is offline  
Old 16-02-2008, 03:05 PM   #4 (permalink)
Wise Old Owl
 
hullap's Avatar
 
Join Date: Dec 2006
Location: delhi
Posts: 1,429
Default Re: Major Linux security hole found

^^ right
hullap is offline  
Old 16-02-2008, 04:15 PM   #5 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,019
Default Re: Major Linux security hole found

they all are as vulnerable
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 16-02-2008, 04:21 PM   #6 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Major Linux security hole found

Exceptions are always there
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 16-02-2008, 05:05 PM   #7 (permalink)
The Devil's Advocate
 
iMav's Avatar
 
Join Date: Mar 2006
Location: Masti Ki Paathshaala
Posts: 7,019
Default Re: Major Linux security hole found

no there are no Exceptions
__________________
"The problem that shows up with the three red lights on the console is a complex interaction with some very complex parts.” - Robbie Bach

http://beingmanan.com
twitter: manan | Last.FM: manan
iMav is offline  
Old 16-02-2008, 08:30 PM   #8 (permalink)
The Dark lord
 
Voldy's Avatar
 
Join Date: Jun 2007
Location: The Riddle house
Posts: 361
Default Re: Major Linux security hole found

Opensource power !!!
__________________
Starting tonight... people will die. I'm a man of my word. - The Joker
"You either die a hero... or you live long enough to see yourself become the villain."
Voldy is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
There are security hole/s in my PC sude QnA (read only) 10 06-04-2006 06:27 PM
Firefox Suffers 'Extremely Critical' Security Hole ferrarif50 Software Q&A 11 19-05-2005 08:04 AM

 
Latest Threads
- by Tenida
- by clinton
- by Anorion

Advertisement




All times are GMT +5.5. The time now is 03:27 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2