Your message dated Mon, 21 Aug 2006 19:54:51 -0400
with message-id <[EMAIL PROTECTED]>
and subject line Security support for woody has ended
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: kernel-image-2.4.18-686
Version: N/A; reported 2004-12-02
Severity: critical
Tags: security
Justification: root security hole

I am sending this from another system than the one in
question; here is the story:

* Default debian-stable install, apt-get update/upgrade everything
  against deb http://security.debian.org/ stable/updates main contrib
  non-free

* 'apt-get install kernel-image-2.4.18-686', run lilo etc.
  and reboot.

* Test do_brk() exploit against system and I'm sitting at
  a root shell.

Is kernel-image-2.4.18-686 vulnerable to do_brk()?  Am I
supposed to install kernel-image-2.4.18-1-686 instead?
If so, why wasn't I warned about this when installing
kernel-image-2.4.18-686?

I am sending from another system since I did 'apt-get
install kernel-image-2.4.18-1-686', ran lilo and now
it isn't getting past init; still sorting that out.

Thanks.



-- System Information
Debian Release: 3.0
Architecture: i386
Kernel: Linux samwise.symonds.net 2.4.24 #2 SMP Tue Feb 10 01:00:24 PST 2004 
i686
Locale: LANG=C, LC_CTYPE=C



--- End Message ---
--- Begin Message ---
And the reported kernel version is long gone from sarge.

-- 
Nathanael Nerode  <[EMAIL PROTECTED]>

A thousand reasons. http://www.thousandreasons.org/
Lies, theft, war, kidnapping, torture, rape, murder...
Get me out of this fascist nightmare!

--- End Message ---

Reply via email to