Sida 1 av 1

Ny vulnerability i linux

Postat: 18 jul 2009, 23:53
av dmz
http://isc.sans.org/diary.html?storyid=6820
Source code for a exploit of a Linux kernel vulnerability has been posted by Brad Spengler (Brad is the author of grsecurity). I have to tell you right now – this was one of the most fascinating bugs I've read about lately.

Why is it so fascinating? Because a source code audit of the vulnerable code would never find this vulnerability (well, actually, it is possible but I assure you that almost everyone would miss it). However, when you add some other variables into the game, the whole landscape changes
.

Re: Ny vulnerability i linux

Postat: 19 jul 2009, 01:16
av Rasmus
Intressant, kompilatorn skapar alltså ett säkerhetshål.
Nu är jag jäkligt trött, men visst skrev han att det nu var fixat?