Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: 2.4.23 ?
PostPosted: Mon Dec 01, 2003 5:50 pm 
Offline
Senior Newbie

Joined: Tue Sep 16, 2003 6:19 pm
Posts: 6
Website: http://mlcastle.net/
AOL: M+L+Castle
Location: New York, NY, US
According to a message from the Debian security list, there is some kind of giant security hole in kernels 2.4.18 ... 2.4.22 -- is it possible to make a 2.4.23 kernel available on linode?

Thx.


Top
   
 Post subject: Re: 2.4.23 ?
PostPosted: Mon Dec 01, 2003 6:46 pm 
Offline
Junior Member

Joined: Thu Sep 18, 2003 1:44 pm
Posts: 46
Website: http://www.officemechanic.com
AOL: schof@mac.com
Location: Los Angeles
mlc wrote:
According to a message from the Debian security list, there is some kind of giant security hole in kernels 2.4.18 ... 2.4.22 -- is it possible to make a 2.4.23 kernel available on linode?

Thx.


This exploit is scary but not the end of the world. (It affects all distributions, not just Debian.) You need a shell account to make it work. Apparently the way the attacker got onto Debian's systems is via a developer who SSH'd into a Debian box from a non-Debian machine that was already compromised by the attacker. The attacker sniffed the password, logged into the Debian machines as a regular user, and then used the exploit to elevate him/herself to root.

However, I agree with mic; I'd like to be running on a kernel not affected by this bug ASAFP. Is switching to 2.4.23-pre8-linode11-5um
recommended, or should we wait for the latest 2.4 kernel to be updated?

References:

http://lists.debian.org/debian-security ... 00212.html

http://www.wiggy.net/debian/

http://developers.slashdot.org/article. ... 01/2133249

_________________
John Schofield
Apple Certified Technical Coordinator
Office Mechanic Consulting
Mac, Unix, and PC Computer Support
www.officemechanic.com


Top
   
 Post subject:
PostPosted: Tue Dec 02, 2003 12:31 am 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
2.4.23-linode16-6um is now available.

Full Thread:

http://www.linode.com/forums/viewtopic.php?t=526

Thanks,
-Chris


Top
   
 Post subject:
PostPosted: Tue Dec 02, 2003 1:14 am 
Offline
Senior Newbie

Joined: Tue Sep 16, 2003 6:19 pm
Posts: 6
Website: http://mlcastle.net/
AOL: M+L+Castle
Location: New York, NY, US
caker wrote:
2.4.23-linode16-6um is now available.


thanks! you rock!

mike


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: mwchase and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group