»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 07-23-2003, 07:03 PM   #1 (permalink)
Registered User
 
jkrohn's Avatar
 
Join Date: Oct 2001
Location: Champaign, IL
Posts: 3,253
jkrohn is on a distinguished road
Send a message via ICQ to jkrohn Send a message via AIM to jkrohn Send a message via Yahoo to jkrohn
Drake users read!!!

For those that are not on the security mailing list.

Quote:
This is an urgent message for all 9.1 users. Please back out of the 24mdk
kernel update and downgrade to 18mdk or 13mdk as soon as you are able. A
problem exists in all kernels (except kernel-secure) where newly created
files are created mode 0666 (world writeable) on any filesystem other than
XFS, including remote NFS mounts.

We are working hard to attempt to get this problem corrected with new
kernels available in the next 24-48hrs.

Thank you.

--
MandrakeSoft Security; http://www.mandrakesecure.net/
Online Security Resource Book; http://linsec.ca/
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FE6F2AFD : 88D8 0D23 8D4B 3407 5BD7 66F9 2043 D0E5 FE6F 2AFD}
Jkrohn

__________________
Jkrohn
jkrohn is offline   Reply With Quote
Old 07-23-2003, 07:06 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
wow!
Now THAT is a security bug!

at least it didnt' change it 777
although may as well at that point cause that system is gonna get hosed!
__________________
<< Insert exceedingly large and overly verbose message of how 1337 you are here including full specs of every vehicle you've ever driven and PC you've owned >>
vass0922 is offline   Reply With Quote
Old 07-23-2003, 07:07 PM   #3 (permalink)
Guest
Guest
 
Posts: n/a
Knew there had to be a reason other than laziness why I didn't upgrade from 18mdk.
  Reply With Quote
Old 07-23-2003, 07:09 PM   #4 (permalink)
Registered User
 
jkrohn's Avatar
 
Join Date: Oct 2001
Location: Champaign, IL
Posts: 3,253
jkrohn is on a distinguished road
Send a message via ICQ to jkrohn Send a message via AIM to jkrohn Send a message via Yahoo to jkrohn
Nothing will get hosed because of this. This is only quite a security risk, and anyone who is serving any kind of remote access should downgrade. Anyone else should be fine, as long as you don't have any net services going.

Jkrohn
__________________
Jkrohn
jkrohn is offline   Reply With Quote
Old 07-24-2003, 07:30 AM   #5 (permalink)
Registered User
 
nukes's Avatar
 
Join Date: Oct 2002
Location: Scotland, UK
Posts: 2,946
nukes is on a distinguished road
Send a message via AIM to nukes Send a message via Yahoo to nukes
What a hole!
That'll be embarrasing.
jkrohn: maybe nothing immediatley, but it opens the system up almost as much as windows does, by allowing every program or user to write anywhere on the drive. (not so bad on NTFS-based systems with permissions enabled and set up though)
vass0922: At least it didn't change it to 877 (SUID root) you mean
__________________
_____
NuKeS
nukes is offline   Reply With Quote
Old 07-26-2003, 03:25 PM   #6 (permalink)
Registered User
 
Germ's Avatar
 
Join Date: Oct 2001
Location: Lat:36.5N, Lon:95.5W
Posts: 1,223
Germ is on a distinguished road
Send a message via AIM to Germ Send a message via Yahoo to Germ
Quote:
Originally posted by nukes
vass0922: At least it didn't change it to 877 (SUID root) you mean
I'm pretty sure he meant 777. That makes it world-writeable.
__________________
How do you set this laser printer to stun??
Germ is offline   Reply With Quote
Old 07-27-2003, 06:02 PM   #7 (permalink)
Registered User
 
ArcticFox's Avatar
 
Join Date: Jan 2003
Location: Wilsonville, OR
Posts: 2,220
ArcticFox is on a distinguished road
Send a message via AIM to ArcticFox Send a message via MSN to ArcticFox Send a message via Yahoo to ArcticFox Send a message via Skype™ to ArcticFox
I guess every OS has it's bad days. This is probably the biggest security breach Linux has had yet, am I wrong?
ArcticFox is offline   Reply With Quote
Old 07-27-2003, 06:45 PM   #8 (permalink)
Registered User
 
Germ's Avatar
 
Join Date: Oct 2001
Location: Lat:36.5N, Lon:95.5W
Posts: 1,223
Germ is on a distinguished road
Send a message via AIM to Germ Send a message via Yahoo to Germ
Mandrake has posted kernel 0.25 which fixes the vulnerability.
__________________
How do you set this laser printer to stun??
Germ is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 05:13 AM.