Re: [rhelv5-list] CVE-2010-3081

2010-09-23 Thread Mete Boz
Am Montag, den 20.09.2010, 12:47 -0600 schrieb Stephen John Smoogen: On Mon, Sep 20, 2010 at 07:08, Gary Gatling gsgat...@eos.ncsu.edu wrote: Will a new kernel be coming out soon to address CVE-2010-3081? I do not believe RHEL-5 is suceptible to this bug. I could not get my RHEL-5

Re: [rhelv5-list] CVE-2010-3081

2010-09-23 Thread Langley, Morgan (GE Capital)
Linux 5 (Tikanga) discussion mailing-list Subject: Re: [rhelv5-list] CVE-2010-3081 Am Montag, den 20.09.2010, 12:47 -0600 schrieb Stephen John Smoogen: On Mon, Sep 20, 2010 at 07:08, Gary Gatling gsgat...@eos.ncsu.edu wrote: Will a new kernel be coming out soon to address CVE-2010-3081? I do

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Linda Wang
Gary Gatling wrote: Will a new kernel be coming out soon to address CVE-2010-3081? It is live on RHN as of late last night/early this morning: RHSA-2010:0704. Thanks, Gary Gatling | ITECS Systems ___ rhelv5-list mailing list

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Hugh Brown
Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 09:19 -0500, Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 08:18 -0400, Linda Wang wrote: It is live on RHN as of late last night/early this morning: RHSA-2010:0704. Confirmed. I had to run 'yum update' twice for the kernel update to

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Cale Fairchild
As far as I understand, from what I read about the Ksplice tool, it that it just tries to detect whether a back door was set up on a system (ie: if it had already been compromised). I do not believe that the intent of the program was not to test if the system was vulnerable. Cale Fairchild

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Linda Wang
Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 09:19 -0500, Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 08:18 -0400, Linda Wang wrote: It is live on RHN as of late last night/early this morning: RHSA-2010:0704. Confirmed. I had to run 'yum update' twice for the

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Linda Wang
Hugh Brown wrote: Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 09:19 -0500, Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 08:18 -0400, Linda Wang wrote: It is live on RHN as of late last night/early this morning: RHSA-2010:0704. Confirmed. I had to run 'yum update' twice for the

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Cale Fairchild
Cale Fairchild wrote: Hugh Brown wrote: Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 09:19 -0500, Robert G. (Doc) Savage wrote: On Tue, 2010-09-21 at 08:18 -0400, Linda Wang wrote: It is live on RHN as of late last night/early this morning: RHSA-2010:0704. Confirmed. I had to run

Re: [rhelv5-list] CVE-2010-3081

2010-09-21 Thread Jon Masters
On Tue, 2010-09-21 at 09:51 -0500, Robert G. (Doc) Savage wrote: I was expecting to see something similar to the output I got for the F13 kernel: $$$ Kernel release: 2.6.34.6-54.fc13.x86_64 !!! Could not find symbol: per_cpu__current_task A symbol required

[rhelv5-list] CVE-2010-3081

2010-09-20 Thread Gary Gatling
Will a new kernel be coming out soon to address CVE-2010-3081? Also, sorry if this is a duplicate. I was having some email issues this morning. Thanks, Gary Gatling | ITECS Systems ___ rhelv5-list mailing list rhelv5-list@redhat.com

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread nodata
On 20/09/10 15:10, Gary Gatling wrote: Will a new kernel be coming out soon to address CVE-2010-3081? Also, sorry if this is a duplicate. I was having some email issues this morning. Thanks, Gary Gatling | ITECS Systems ___ rhelv5-list mailing

[rhelv5-list] CVE-2010-3081

2010-09-20 Thread Gary Gatling
Will a new kernel be coming out soon to address CVE-2010-3081? Thanks, Gary Gatling | ITECS Systems ___ rhelv5-list mailing list rhelv5-list@redhat.com https://www.redhat.com/mailman/listinfo/rhelv5-list

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Akemi Yagi
On Mon, Sep 20, 2010 at 6:10 AM, Gary Gatling gsgat...@ncsu.edu wrote: Will a new kernel be coming out soon to address CVE-2010-3081? Also, sorry if this is a duplicate. I was having some email issues this morning. Early this week according to:

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread John Haxby
On 20 September 2010 14:10, Gary Gatling gsgat...@ncsu.edu wrote: Will a new kernel be coming out soon to address CVE-2010-3081? For what it's worth, any CVE id is a suitable bug alias for Red Hat's bugzilla, eg https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3081 jch

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Chris Adams
Once upon a time, John Haxby j...@thehaxbys.co.uk said: For what it's worth, any CVE id is a suitable bug alias for Red Hat's bugzilla, eg https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3081 Does anybody know what the holdup is with releasing a fixed kernel? Per the BZ, Red Hat has

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Stephen John Smoogen
On Mon, Sep 20, 2010 at 07:08, Gary Gatling gsgat...@eos.ncsu.edu wrote: Will a new kernel be coming out soon to address CVE-2010-3081? I do not believe RHEL-5 is suceptible to this bug. I could not get my RHEL-5 x86_64 to 'root' but that does not mean I was doing it right. Thanks, Gary

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Stephen John Smoogen
On Mon, Sep 20, 2010 at 12:47, Stephen John Smoogen smo...@gmail.com wrote: On Mon, Sep 20, 2010 at 07:08, Gary Gatling gsgat...@eos.ncsu.edu wrote: Will a new kernel be coming out soon to address CVE-2010-3081? I do not believe RHEL-5 is suceptible to this bug. I could not get my RHEL-5

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Robert G. (Doc) Savage
On Mon, 2010-09-20 at 09:08 -0400, Gary Gatling wrote: Will a new kernel be coming out soon to address CVE-2010-3081? Thanks, Gary Gatling | ITECS Systems Gary, I was concerned about this until I read this: http://isc.sans.edu/diary.html?storyid=9574 I downloaded and ran the

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Stephen John Smoogen
On Mon, Sep 20, 2010 at 13:06, Robert G. (Doc) Savage dsav...@peaknet.net wrote: On Mon, 2010-09-20 at 09:08 -0400, Gary Gatling wrote: Will a new kernel be coming out soon to address CVE-2010-3081? Thanks, Gary Gatling      | ITECS Systems Gary, I was concerned about this until I read

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Chris Adams
Once upon a time, Robert G. (Doc) Savage dsav...@peaknet.net said: I was concerned about this until I read this: http://isc.sans.edu/diary.html?storyid=9574 I downloaded and ran the diagnose-2010-3081 binary on my RHEL55 server and was relieved to see: $ ./diagnose-2010-3081

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Robert G. (Doc) Savage
On Mon, 2010-09-20 at 14:06 -0500, Robert G. (Doc) Savage wrote: I was concerned about this until I read this: http://isc.sans.edu/diary.html?storyid=9574 I downloaded and ran the diagnose-2010-3081 binary on my RHEL55 server and was relieved to see: $ ./diagnose-2010-3081

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Gary Gatling
Hey guys. I just compiled this: http://seclists.org/fulldisclosure/2010/Sep/268 on a 32 bit machine and indeed, RHEL 5 is affected. (The first exploit code I saw over the weekend did not work but this one did) I compiled on 32 bit kernel and ran on 64 bit kernel (2.6.18-194.11.3.el5) and

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread John Haxby
On 20 September 2010 18:20, Chris Adams cmad...@hiwaay.net wrote: Once upon a time, John Haxby j...@thehaxbys.co.uk said: For what it's worth, any CVE id is a suitable bug alias for Red Hat's bugzilla, eg https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3081 Does anybody know what

Re: [rhelv5-list] CVE-2010-3081

2010-09-20 Thread Chris Adams
Once upon a time, Gary Gatling gsgat...@ncsu.edu said: on a 32 bit machine and indeed, RHEL 5 is affected. (The first exploit code I saw over the weekend did not work but this one did) I compiled on 32 bit kernel and ran on 64 bit kernel (2.6.18-194.11.3.el5) and got root. scary. I've added