Re: Kernels 2.2 and 2.4 exploit (ALL VERSION WHAT I HAVE TESTED

Alan Cox (alan@lxorguk.ukuu.org.uk)
19 Mar 2003 16:13:05 +0000


On Wed, 2003-03-19 at 14:55, Anders Gustafsson wrote:
> If access can't be shut down while compiling the new kernel
>
> echo /foo/bar/doesnotexist >/proc/sys/kernel/modprobe
>
> would help, wouldn't it?

Against the default exploit circulating yes, in the general
case we don't believe so. Realistically we are a day or two
before a major war breaks out with huge amounts of bad
feeling involved. It is not the time to put off security
updates, especially if you have a potentially US or UK domain
name/address range

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/