PDA

View Full Version : Linux Kernel Information Disclosure and Security Bypass


Searching_ _ _
March 24th, 2009, 12:01 PM
-{ Quote: "Some security issues have been reported in the Linux Kernel, which can be exploited by malicious, local users to disclose potentially sensitive information and by malicious users to bypass certain security restrictions.

1) A security issue is caused due to an error when storing eCryptfs headers, which can be exploited to disclose certain kernel memory.

2) A security issue is caused due to nfsd not properly dropping the "CAP_MKNOD" capability for unprivileged users, which can be exploited to create device nodes.
" }-
http://secunia.com/advisories/34422/

tlu
March 28th, 2009, 08:07 AM
Who cares? Secunia themselves say that the leak is "less critical". And a fix by the Linux developers is already on its way.

Arup
March 28th, 2009, 09:30 AM
Again, both are local exploits and they can be easily blocked, nothing serious like a OS hole allowing remote code execution.