Missing security fixes for Woody kernel

2004-11-25 Thread Philip Ross
The latest 2.4 kernel for Woody (kernel-image-2.4.18-1-686 version 2.4.18-13.1) is still vulnerable to the FPU crash CAN-2004-0554 discovered back in June 2004 and fixed in the 2.4.27 kernel. The code available at http://www.securiteam.com/exploits/5ZP0N0AD5A.html will crash an up to date Woody

Re: [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution

2004-10-12 Thread Philip Ross
Martin Schulze wrote: - -- Debian Security Advisory DSA 563-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze October 12th, 2004 http://www.d

Re: CAN 2004-0415 [linux kernel]

2004-08-13 Thread Philip Ross
Kevin B. McCarty wrote: Have you guys seen this advisory yet? It looks rather serious: http://isec.pl/vulnerabilities/isec-0016-procleaks.txt Apparently this is fixed in 2.4.27-rc5 (don't know about 2.6 series): http://lwn.net/Articles/96485/ The fix should probably go into Debian kernels in sarge