Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread nnex
Hi all. I'm confirm exploit is working on Debian wheezy with kernel 3.2.0-4-rt-amd64 with gcc -O2 options On 05/15/2013 12:20 AM, Gavin wrote: On 14 May 2013 19:41, Gerald Turner wrote: Gavin writes: On 14 May 2013 18:36, John Andreasson wrote: Was just alerted of a kernel bug in RHEL [1

Re: [SECURITY] [DSA 2668-1] linux-2.6 security update

2013-05-14 Thread Jon Marshall
Apologies, hit the wrong reply to! Please ignore and thanks for all the good work. On Tue, May 14, 2013 at 09:15:48PM +0100, Jon Marshall wrote: > Saw this earlier, apparently there is a serious issue that affects all of the > kernels up to 3.8 > > Will do a security thing tomorrow, if I get a ch

Re: [SECURITY] [DSA 2668-1] linux-2.6 security update

2013-05-14 Thread Jon Marshall
Saw this earlier, apparently there is a serious issue that affects all of the kernels up to 3.8 Will do a security thing tomorrow, if I get a chance, but it has been a while since we've had a look at it, my fault. Will update once I've reviewed. On Tue, May 14, 2013 at 01:14:29PM -0600, dann fra

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread Gavin
On 14 May 2013 19:41, Gerald Turner wrote: > Gavin writes: >> On 14 May 2013 18:36, John Andreasson wrote: >>> Was just alerted of a kernel bug in RHEL [1], but when testing the >>> sample code on Wheezy as an unprivileged user it successfully gives >>> me a root prompt. Kind of suboptimal. :-(

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread Gerald Turner
Gavin writes: > On 14 May 2013 18:36, John Andreasson wrote: >> Was just alerted of a kernel bug in RHEL [1], but when testing the >> sample code on Wheezy as an unprivileged user it successfully gives >> me a root prompt. Kind of suboptimal. :-( >> >> Any idea when this is fixed? >> >> [1] https

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread John Andreasson
On Tuesday, May 14, 2013, Gavin wrote: > On 14 May 2013 18:36, John Andreasson > > wrote: > > > > Hi. > > > > Was just alerted of a kernel bug in RHEL [1], but when testing the > sample code on Wheezy as an unprivileged user it successfully gives me a > root prompt. Kind of suboptimal. :-( > > > >

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread dann frazier
On Tue, May 14, 2013 at 09:36:12AM -0700, John Andreasson wrote: > Hi. > > Was just alerted of a kernel bug in RHEL [1], but when testing the sample > code on Wheezy as an unprivileged user it successfully gives me a root > prompt. Kind of suboptimal. :-( > > Any idea when this is fixed? We're i

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread Gavin
On 14 May 2013 18:36, John Andreasson wrote: > > Hi. > > Was just alerted of a kernel bug in RHEL [1], but when testing the sample > code on Wheezy as an unprivileged user it successfully gives me a root > prompt. Kind of suboptimal. :-( > > Any idea when this is fixed? > > [1] https://bugzilla.

Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread John Andreasson
Hi. Was just alerted of a kernel bug in RHEL [1], but when testing the sample code on Wheezy as an unprivileged user it successfully gives me a root prompt. Kind of suboptimal. :-( Any idea when this is fixed? [1] https://bugzilla.redhat.com/show_bug.cgi?id=962792