On Sat, 13 May 2006 11:32:49 +0200
Simon Strandman <[EMAIL PROTECTED]> wrote:

> Kevin F. Quinn (Gentoo) skrev:
> > On Fri, 12 May 2006 10:49:22 +0200
> > Simon Strandman <[EMAIL PROTECTED]> wrote:
> >
> >> I installed modular X on my server running hardened.
> >
> > X on a server?  If it's just for the libs that's ok, but running
> > the X server itself is risky on a server as it's huge and suid so
> > flaws can easily gain root access.  One such was discovered just
> > the other week
> > (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1526). 
> I have my reasons. I need to run VNC on it.

ok; just remember that by building vanilla you lose PIE and SSP as well
(either of which can reduce the impact of buffer overflow exploits
from privilege escalation to denial-of-service or less).  For anyone
else considering it, hardened advise sticking with 6.8 for now.

-- 
Kevin F. Quinn

Attachment: signature.asc
Description: PGP signature

Reply via email to