x404.co.uk http://x404.co.uk/forum/ |
|
Atttack exploits fully-patched Linux kernel - The Register http://x404.co.uk/forum/viewtopic.php?f=19&t=1839 |
Page 1 of 1 |
Author: | Linux_User [ Sat Jul 18, 2009 2:14 am ] | |||||||||
Post subject: | Atttack exploits fully-patched Linux kernel - The Register | |||||||||
Courtesy of The Register |
Author: | gavomatic57 [ Sat Jul 18, 2009 6:40 am ] |
Post subject: | Re: Atttack exploits fully-patched Linux kernel - The Register |
Bit worrying that. Fortunately Ubuntu is still on the 2.6.29 if I'm not mistaken. That said, if it has been "inherited from UNIX", I wonder if OSX is affected? |
Author: | big_D [ Sat Jul 18, 2009 8:28 am ] |
Post subject: | Re: Atttack exploits fully-patched Linux kernel - The Register |
Given that .30 has only just been released and most distros are on older versions of the Kernel, the article doesn't make sense, unless it works on previous versions, up to and including the 30 release... ![]() The Setuid principle comes from UNIX, but the code they use doesn't. It will also depend on the compiler and the optimisation options that are selected - looking at the article. The code itself doesn't have a flaw, but when combined with certain methods of optimisation, the check is cancelled out by the compiler! If the compiler doesn't cancel out the check during the optimisation process, then the vulnerability shouldn't show up... |
Author: | forquare1 [ Sat Jul 18, 2009 10:38 am ] |
Post subject: | Re: Atttack exploits fully-patched Linux kernel - The Register |
It's a very interesting bug. It's amazing what the compiler will do to your code! I think it's bad that Torvalds didn't seem to think it was a problem at the start. |
Author: | JJW009 [ Sat Jul 18, 2009 10:43 am ] | |||||||||
Post subject: | Re: Atttack exploits fully-patched Linux kernel - The Register | |||||||||
Indeed. I'm rather shocked. How on earth are you supposed to predict or debug things like that? My excuse from now on: "The compiler did it!" |
Author: | forquare1 [ Sat Jul 18, 2009 10:49 am ] | |||||||||
Post subject: | Re: Atttack exploits fully-patched Linux kernel - The Register | |||||||||
I guess we just have to learn and try to understand a bit more, this article reminds me of a blog post a collegue posted ages ago, clicky, not a bug, but another interesting thing the compiler will do with your code. |
Page 1 of 1 | All times are UTC |
Powered by phpBB® Forum Software © phpBB Group https://www.phpbb.com/ |