openSUSE Forums > Applications » Has openSUSE patched this? How protect against this?

Go Back   openSUSE Forums > Applications
Forums FAQ Members List Search Today's Posts Mark Forums Read


Applications Questions about desktops (KDE, Gnome, XFCE, etc.), software applications (configuration, usage, bugs, documentation)

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-Nov-2009, 11:44
Busy Penguin
 
Join Date: Oct 2008
Posts: 433
6tr6tr hasn't been rated much yet
Default Has openSUSE patched this? How protect against this?

Bug in latest Linux gives untrusted users root access • The Register

Quote:
"The null pointer dereference flaw was only fixed in the upcoming 2.6.32 release candidate of the Linux kernel, making virtually all production versions in use at the moment vulnerable. While attacks can be prevented by implementing a common feature known as mmap_min_addr, the RHEL distribution... doesn't properly implement that protection... The... bug is mitigated by default on most Linux distributions, thanks to their correct implementation of the mmap_min_addr feature. ... [Spengler] said many other Linux users are also vulnerable because they run older versions or are forced to turn off [mmap_min_addr] to run certain types of applications."
Reply With Quote
  #2 (permalink)  
Old 04-Nov-2009, 12:49
buckesfeld's Avatar
Global Moderator
 
Join Date: Mar 2008
Location: Bochum, Germany
Posts: 2,563
buckesfeld has a spectacular reputation aura aboutbuckesfeld has a spectacular reputation aura aboutbuckesfeld has a spectacular reputation aura aboutbuckesfeld has a spectacular reputation aura about
Send a message via AIM to buckesfeld
Default Re: Has openSUSE patched this? How protect against this?

* 6tr6tr wrote, On 11/04/2009 06:46 PM:
>
> 'Bug in latest Linux gives untrusted users root access • The Register'
> (http://www.theregister.co.uk/2009/11...vulnerability/)
>



There is most definitely a patched kernel being prepared for the openSUSE versions still supported. Keep an eye on your updater applet.
Don't panic, it's a local problem.

Uwe
Reply With Quote
  #3 (permalink)  
Old 04-Nov-2009, 13:28
Wise Penguin
 
Join Date: Mar 2009
Posts: 1,824
Akoellh is a reputation jewel in the roughAkoellh is a reputation jewel in the roughAkoellh is a reputation jewel in the roughAkoellh is a reputation jewel in the roughAkoellh is a reputation jewel in the rough
Default Re: Has openSUSE patched this? How protect against this?

Code:
cat /proc/sys/vm/mmap_min_addr
65536
__________________
“Never attribute to malice that which can be adequately explained by stupidity.” (R.J. Hanlon)
Reply With Quote
  #4 (permalink)  
Old 04-Nov-2009, 15:34
markcynt's Avatar
Explorer Penguin
 
Join Date: Oct 2008
Location: Lakeland, Florida
Posts: 118
markcynt hasn't been rated much yet
Default Re: Has openSUSE patched this? How protect against this?

Looks like we're safe for the most part.

Quote:
The latest bug is mitigated by default on most Linux distributions, thanks to their correct implementation of the mmap_min_addr feature. But to make RHEL compatible with a larger body of applications, that distribution is vulnerable to attack even when the OS shows the feature is enabled, Spengler said.
"They're putting their users at risk," he said. "They're basically the only distribution that's still vulnerable to this class of attack."
A Red Hat spokeswoman said patches for the versions 4 and 5 of RHEL and MRG are available here. An update for RHEL 3 is in testing and should be released soon.
He said many other Linux users are also vulnerable because they run older versions or are forced to turn off the feature to run certain types of applications.
__________________
P5N-E SLI, Core2Duo E6850 @ 3GHZ, 2 GB DDR2 800MHZ
EVGA 8800GTS 320MB, 2x320GB
Arctic Cooling Freezer 7 Pro
OpenSuse 11.2, KDE 4.3
Reply With Quote
  #5 (permalink)  
Old 04-Nov-2009, 19:24
Busy Penguin
 
Join Date: Oct 2008
Posts: 433
6tr6tr hasn't been rated much yet
Default Re: Has openSUSE patched this? How protect against this?

Quote:
Originally Posted by buckesfeld View Post
* 6tr6tr wrote, On 11/04/2009 06:46 PM:
>
> 'Bug in latest Linux gives untrusted users root access • The Register'
> (Bug in latest Linux gives untrusted users root access • The Register)
>



There is most definitely a patched kernel being prepared for the openSUSE versions still supported. Keep an eye on your updater applet.
Don't panic, it's a local problem.

Uwe
What do you mean by "it's a local problem"?
Reply With Quote
  #6 (permalink)  
Old 05-Nov-2009, 11:06
buckesfeld's Avatar
Global Moderator
 
Join Date: Mar 2008
Location: Bochum, Germany
Posts: 2,563
buckesfeld has a spectacular reputation aura aboutbuckesfeld has a spectacular reputation aura aboutbuckesfeld has a spectacular reputation aura aboutbuckesfeld has a spectacular reputation aura about
Send a message via AIM to buckesfeld
Default Re: Has openSUSE patched this? How protect against this?

* 6tr6tr wrote, On 11/05/2009 02:26 AM:
> What do you mean by "it's a local problem"?


The issue allows local users to gain root rights, AFAIK. Not more. Let's say you have a desktop install with only one user and no ssh or telnet running, you are pretty safe.

Uwe
Reply With Quote
Reply

Bookmarks


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




 

Search Engine Friendly URLs by vBSEO 3.3.0 RC2