Ik zag hem hier nog niet staan. Het gaat om een bug in de kernel van RHEL 6 (waar CentOS, ClearOS, scientificlinux, etc op gebaseerd is).
https://access.redhat.com/security/cve/CVE-2013-2094
Wat meer info /patches
patch
patch
wht.com

Ik zag hem hier nog niet staan. Het gaat om een bug in de kernel van RHEL 6 (waar CentOS, ClearOS, scientificlinux, etc op gebaseerd is).
https://access.redhat.com/security/cve/CVE-2013-2094
Wat meer info /patches
patch
patch
wht.com
Laatst gewijzigd door Yourwebhoster; 15/05/13 om 19:22.
Met vriendelijke groet, Yourwebhoster.eu - Managed VPS diensten met Epyc performance op 100% SSDs
Lees hier de webhostingtalk.nl forum regels en voorwaarden!
BRON: Arstechnica
For years, the Linux operating system has contained a high-severity vulnerability that gives untrusted users with restricted accounts nearly unfettered "root" access over machines, including servers running in shared Web hosting facilities and other sensitive environments. Surprisingly, most users remain wide open even now, more than a month after maintainers of the open-source OS quietly released an update that patched the gaping hole.
The severity of the bug, which resides in the Linux kernel's "perf," or performance counters subsystem, didn't become clear until Tuesday, when attack code exploiting the vulnerability became publicly available (note: some content on this site is not considered appropriate in many work environments). The new script can be used to take control of servers operated by many shared Web hosting providers, where dozens or hundreds of people have unprivileged accounts on the same machine. Hackers who already have limited control over a Linux machine—for instance, by exploiting a vulnerability in a desktop browser or a Web application—can also use the bug to escalate their privileges to root. The flaw affects versions of the Linux kernel from 2.6.37 to 3.8.8 that have been compiled with the CONFIG_PERF_EVENTS kernel configuration option.
Wordt weer testen en patchen helaas :-(
Voor Redhat en soortgenoten schijnt er al een workaround te zijn maar zelf wacht ik liever op een wat meer geteste patch..
https://bugzilla.redhat.com/show_bug.cgi?id=962792#c13
Netbulae - Hosted Solutions

Ik heb het samengevoegd.
Met vriendelijke groet, Yourwebhoster.eu - Managed VPS diensten met Epyc performance op 100% SSDs
Lees hier de webhostingtalk.nl forum regels en voorwaarden!
Inmiddels is er een patch voor CentOS 6. Kan gewoon met yum update installeren.
Yisp.nl - High bandwidth solutions in YISP-AS(58073) - www.yisp.nl