Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-15 Thread Riku Valli
On 05/15/2013 01:50 PM, Kees de Jong wrote: > Gavin, did you use the right exploit? The output looks like it's > designed for a 2.6.37 kernel. I don't have a computer near me to check > the exploit myself. Could you please verify you used the right exploit? > Thanks! Bug is in 2.6.37-3.8.8, fixed

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-15 Thread Gavin
On 15 May 2013 12:50, Kees de Jong wrote: > Gavin, did you use the right exploit? The output looks like it's designed > for a 2.6.37 kernel. I don't have a computer near me to check the exploit > myself. Could you please verify you used the right exploit? Thanks! Hi Kees, I grabbed the source fr

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-15 Thread Kees de Jong
Gavin, did you use the right exploit? The output looks like it's designed for a 2.6.37 kernel. I don't have a computer near me to check the exploit myself. Could you please verify you used the right exploit? Thanks!

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread nnex
Hi all. I'm confirm exploit is working on Debian wheezy with kernel 3.2.0-4-rt-amd64 with gcc -O2 options On 05/15/2013 12:20 AM, Gavin wrote: On 14 May 2013 19:41, Gerald Turner wrote: Gavin writes: On 14 May 2013 18:36, John Andreasson wrote: Was just alerted of a kernel bug in RHEL [1

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread Gavin
On 14 May 2013 19:41, Gerald Turner wrote: > Gavin writes: >> On 14 May 2013 18:36, John Andreasson wrote: >>> Was just alerted of a kernel bug in RHEL [1], but when testing the >>> sample code on Wheezy as an unprivileged user it successfully gives >>> me a root prompt. Kind of suboptimal. :-(

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread Gerald Turner
Gavin writes: > On 14 May 2013 18:36, John Andreasson wrote: >> Was just alerted of a kernel bug in RHEL [1], but when testing the >> sample code on Wheezy as an unprivileged user it successfully gives >> me a root prompt. Kind of suboptimal. :-( >> >> Any idea when this is fixed? >> >> [1] https

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread John Andreasson
On Tuesday, May 14, 2013, Gavin wrote: > On 14 May 2013 18:36, John Andreasson > > wrote: > > > > Hi. > > > > Was just alerted of a kernel bug in RHEL [1], but when testing the > sample code on Wheezy as an unprivileged user it successfully gives me a > root prompt. Kind of suboptimal. :-( > > > >

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread dann frazier
On Tue, May 14, 2013 at 09:36:12AM -0700, John Andreasson wrote: > Hi. > > Was just alerted of a kernel bug in RHEL [1], but when testing the sample > code on Wheezy as an unprivileged user it successfully gives me a root > prompt. Kind of suboptimal. :-( > > Any idea when this is fixed? We're i

Re: Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread Gavin
On 14 May 2013 18:36, John Andreasson wrote: > > Hi. > > Was just alerted of a kernel bug in RHEL [1], but when testing the sample > code on Wheezy as an unprivileged user it successfully gives me a root > prompt. Kind of suboptimal. :-( > > Any idea when this is fixed? > > [1] https://bugzilla.

Wheezy is vulnerable to CVE-2013-2094

2013-05-14 Thread John Andreasson
Hi. Was just alerted of a kernel bug in RHEL [1], but when testing the sample code on Wheezy as an unprivileged user it successfully gives me a root prompt. Kind of suboptimal. :-( Any idea when this is fixed? [1] https://bugzilla.redhat.com/show_bug.cgi?id=962792