Free Republic
Browse · Search
General/Chat
Topics · Post Article


1 posted on 11/24/2006 11:35:42 AM PST by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies ]


To: Swordmaker; ShadowAce; martin_fierro; Salo

fyi


2 posted on 11/24/2006 11:37:27 AM PST by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Ernest_at_the_Beach

This is not new. The flaw has been noted a number of times over the past few months.


3 posted on 11/24/2006 11:42:26 AM PST by jimtorr
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Ernest_at_the_Beach

Already posted over here:

http://www.freerepublic.com/focus/f-chat/1742381/posts


5 posted on 11/24/2006 12:33:04 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: All; Ernest_at_the_Beach
"In addition to being used to compromise a computer, the flaw could be exploited by malicious local users to gain escalated privileges to the system, the security company said."

Balderdash... Not one demonstration of such an escalation has been shown... Certainly, Secunia has not demonstrated an escalation of privileges... nor has the "Month of Kernal Bugs" demonstrated one.

The OS merely crashes, creating a local "denial-of-service" condition, requiring a hardware restart. How is that going to allow a "malicious local user" to escalate his privileges? Unless he already knows an administrator or root name and password he can only log back on as the same user as before with the same privleges. And if he does know those names and passwords, he merely has to switch user.and there's no need to crash the system to do that.

Certainly this is a kernal flaw... and it needs to be fixed.

But it is not the "Critical" security hole Secunia, and subsequent re-printers of their FUD such as C-Net, are frothing at the mouth about.

It isn't even a long-term Denial-of-Service situation... for this to happen a local user has to be sitting at the computer trying to open a .dmg file. He will certainly notice the kernal panic and restart the computer, restoring the service within a minute or two.

6 posted on 11/24/2006 12:49:02 PM PST by Swordmaker (Remember, the proper pronunciation of IE is "AAAAIIIIIEEEEEEE!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

8 posted on 11/24/2006 5:01:55 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Ernest_at_the_Beach
a blog devoted to a 'Month of Kernel Bugs' campaign which promises to reveal details of a new flaw in low-level software every day this month.

Uh, so what happened to November 1 - November 21?

9 posted on 11/24/2006 6:29:42 PM PST by Dont Mention the War (Giuliani '08: Why not p. o. BOTH sides?)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson