Re: BF kernels (was: [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386))

2004-04-18 Thread Horst Pflugstaedt
On Sat, Apr 17, 2004 at 10:00:23AM -0400, Michael Stone wrote: On Thu, Apr 15, 2004 at 08:19:24PM +1000, Joshua Goodall wrote: In other words, people are ready to pounce, and that short gap of time after server installation and before installing patched code cannot be considered safe. Quite

Re: BF kernels (was: [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386))

2004-04-18 Thread Horst Pflugstaedt
On Sat, Apr 17, 2004 at 10:00:23AM -0400, Michael Stone wrote: On Thu, Apr 15, 2004 at 08:19:24PM +1000, Joshua Goodall wrote: In other words, people are ready to pounce, and that short gap of time after server installation and before installing patched code cannot be considered safe. Quite

Re: BF kernels (was: [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386))

2004-04-17 Thread Michael Stone
On Thu, Apr 15, 2004 at 08:19:24PM +1000, Joshua Goodall wrote: In other words, people are ready to pounce, and that short gap of time after server installation and before installing patched code cannot be considered safe. Quite the opposite. Note that if you're doing a network install you can

Re: BF kernels (was: [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386))

2004-04-17 Thread Michael Stone
On Thu, Apr 15, 2004 at 08:19:24PM +1000, Joshua Goodall wrote: In other words, people are ready to pounce, and that short gap of time after server installation and before installing patched code cannot be considered safe. Quite the opposite. Note that if you're doing a network install you

Re: BF kernels (was: [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386))

2004-04-15 Thread Joshua Goodall
On Thu, 15 Apr 2004 07:56 pm, Tim Nicholas wrote: If I recall correctly it is assumed that users will not run on the boot floppy kernels after the initial system installation. They are expected to install a more appropriate kernel after finishing the install. As such there will be no patch

Re: BF kernels (was: [DSA 479-2] New Linux 2.4.18 packages fix local root exploit (i386))

2004-04-15 Thread Joshua Goodall
On Thu, 15 Apr 2004 07:56 pm, Tim Nicholas wrote: If I recall correctly it is assumed that users will not run on the boot floppy kernels after the initial system installation. They are expected to install a more appropriate kernel after finishing the install. As such there will be no patch