Announcement

Collapse
No announcement yet.

Oh noooo, more Linux vulnerabilities...now without testing

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Oh noooo, more Linux vulnerabilities...now without testing

    Yet another couple vunerabilities for the Linux kernel. Pretty astonishing there are so many considering that it is so secure.

    Apparently they also don't test these fixes very well. They attribute their ability to get releases out quickly to their being open source, but anyone could release the fixes so early. The reason they're going out so early is they don't do testing, let alone the large-scale testing corporations like MS have to do on patches.

    .xyz is for every website, everywhere.® We offer the most flexible and affordable domain names to create choice for the next generation of internet users.


    Security flaws force Linux kernel upgrade
    Last modified: January 5, 2004, 11:34 AM PST
    By Robert Lemos
    Staff Writer, CNET News.com

    Open-source developers released a new version of the Linux kernel Monday in a move aimed at quickly fixing several bugs--among them two serious security flaws.

    The 2.4.24 upgrade to the Linux kernel comes a month after the release of the previous version of the core system software and only includes patches for six software issues, including the two flaws.

    The release is intended to prompt users to upgrade quickly, said Marcelo Tosatti, the maintainer of the 2.4 kernel series and a Linux developer for data center management company Cyclades.

    "These security issues need to be fixed as soon as possible," Tosatti told CNET News.com in an interview Monday. As maintainer, Tosatti decides what changes can be made to the kernel and when to release new versions of the core system software for Linux.

    The most serious flaw, which occurs in a function used by virtual memory, resembles a vulnerability fixed in late November that had been exploited by unknown attackers to control several key Linux servers open-source developers use. Both flaws allow an intruder to increase the privileges of a normal user account to the same level as the system's owner.

    Tosatti said that once it became clear that the latest flaw could be used to circumvent security on Linux systems, he and other developers decided to immediately release the fixes. The move follows decisions by the kernel developers to curtail new features in the 2.4 kernel series in order to get developers and users to move to the next generation of core Linux software, the 2.6 kernel. The final set of features that had been intended for this release of the kernel have been postponed until the next version, he said.

    "It is good that I have the ability--because this is open source--to release the code so quickly," Tosatti said.

    The second security flaw results in a device driver problem that could allow an intruder to read some memory the kernel uses.

    The latest version of the kernel can be downloaded from Kernel.org. Patches for specific Linux distributions can be downloaded from their developers.
    This is what you call Trustworthy Computing.
    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
    Ben Kenobi: "That means I'm doing something right. "

  • #2
    Linux vulnerable. Linux bad! Linux users, don't use Linux! Switch to Microsoft! We MS-users, and especially I, with my glorious Windows Millenium Edition, have much better, and more trustworthy, OS's!

    Comment


    • #3
      Hooray!
      "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
      Ben Kenobi: "That means I'm doing something right. "

      Comment


      • #4
        Originally posted by VJ
        glorious Windows Millenium Edition
        If I were drinking a glass of milk, I would have spit it across the room.
        Tutto nel mondo è burla

        Comment


        • #5
          People ought to use AmigaOS. Doesn't have any of these nasty security vulnerablilities, or, for that matter, any viruses out there that affect it.

          Then again, you'd need an Amiga to run it.
          "Paul Hanson, you should give Gibraltar back to the Spanish" - Paiktis, dramatically over-estimating my influence in diplomatic circles.

          Eyewerks - you know you want to visit. No really, you do. Go on, click me.

          Comment


          • #6
            Still love your avatar VJ, its the best!
            Que l’Univers n’est qu’un défaut dans la pureté de Non-être.

            - Paul Valery

            Comment


            • #7
              Re: Oh noooo, more Linux vulnerabilities...now without testing

              Originally posted by Asher

              The reason they're going out so early is they don't do testing, let alone the large-scale testing corporations like MS have to do on patches.
              Apparently this large-scale testing has not been of much use either...
              I watched you fall. I think I pushed.

              Comment


              • #8
                the large-scale testing corporations like MS have to do

                Poor MicroDoze...
                Within weeks they'll be re-opening the shipyards
                And notifying the next of kin
                Once again...

                Comment


                • #9
                  MicroDoze...that one's so innovative it is neither insulting nor funny. Keep up the good work.
                  "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                  Ben Kenobi: "That means I'm doing something right. "

                  Comment


                  • #10
                    Originally posted by Asher
                    MicroDoze...that one's so innovative it is neither insulting nor funny. Keep up the good work.
                    I know, just trying to keep the $ out of it
                    Within weeks they'll be re-opening the shipyards
                    And notifying the next of kin
                    Once again...

                    Comment


                    • #11
                      MICRO$OFT $UXXOR$!!!!111!!!!111!!!1!

                      Why can't people just call it Microsoft? At least Windows users have the decency to call Linux Linux.

                      Comment


                      • #12
                        Because the people who hate Microsoft tend to be waiting to grow up still.

                        Imagine if people called Linux Linsux or Sinux.
                        "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                        Ben Kenobi: "That means I'm doing something right. "

                        Comment


                        • #13
                          Careful Hueij, Asher gets very protective of his precious
                          Speaking of Erith:

                          "It's not twinned with anywhere, but it does have a suicide pact with Dagenham" - Linda Smith

                          Comment


                          • #14
                            so the solution is to throw Bill Gates down into Mount Doom?
                            I watched you fall. I think I pushed.

                            Comment


                            • #15
                              Originally posted by VJ
                              Linux vulnerable. Linux bad! Linux users, don't use Linux! Switch to Microsoft! We MS-users, and especially I, with my glorious Windows Millenium Edition, have much better, and more trustworthy, OS's!
                              (\__/) 07/07/1937 - Never forget
                              (='.'=) "Claims demand evidence; extraordinary claims demand extraordinary evidence." -- Carl Sagan
                              (")_(") "Starting the fire from within."

                              Comment

                              Working...
                              X