Local root exploit Linux kernel <2.6.24.1
11-02-2008,15:56 doorSirDice
De dames en heren linux gebruikers hier doen er verstandig
aan even de kernel te updaten.

One of our readers, Chris, said,
http://it.slashdot.org/it/08/02/10/2011257.shtml apparently
affecting RHEL5 and OpenSuSE 10.3 amongst other popular
distributions, could be rather bad news.”

Gordon sent us this quote from Slashdot: "This local root
exploit (Debian, Ubuntu) seems to work everywhere I try it,
as long as it's a Linux kernel version 2.6.17 to 2.6.24.1.
If you don't trust your users (which you shouldn't), better
compile a new kernel without vmsplice."


http://isc.sans.org/diary.html?storyid=3968