LOL 'malicious local users'

Story: Title: Linux Kernel "get_fdb_entries()" Integer Overflow ...Total Replies: 2
Author Content
tuxchick

Nov 30, 2006
12:05 PM EDT
I love the contrast between Windows and Linux security vulnerabilities, like this one:

"The vulnerability is caused due to an integer overflow within the "get_fdb_entries()" function in net/bridge/br_ioctl.c. This can be exploited to cause a buffer overflow via specially crafted ioctl() requests.

Successful exploitation may allow the execution of arbitrary code with escalated privileges.

SOLUTION: Update to version 2.6.18.4 or 2.6.19."

Typical Windows vulnerability:

"Visit the wrong Web site and your system and all windows systems it has ever exchanged so much as a single packet with are now fully pwned. Welcome to the botnet! Your stats today: 23,000,000 pump n dump spams spewed forth. Very good! Thank you for purchasing high-end hardware and having 24x7 broadband!

Solution? Bwahahaaa!"

Libervis

Nov 30, 2006
12:47 PM EDT
Lol, I'm not a coder nor a security expert, but this is funny. :D
swbrown

Nov 30, 2006
4:16 PM EDT
It's still rather sad that the Linux kernel quite often has security problems even in the core kernel portion. It's become the sendmail of kernels. That's nothing worth defending, it's something worth fixing.

Posting in this forum is limited to members of the group: [ForumMods, SITEADMINS, MEMBERS.]

Becoming a member of LXer is easy and free. Join Us!