Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 9 Oct 2014 13:06:02 +0200
From: rf@...eap.de
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2014-7975: 0-day umount denial of service

>>>>> "Andy" == Andy Lutomirski <luto@...capital.net> writes:

    Andy> I just screwed up and typoed my git send-email command, so
    Andy> there's now a publicly available exploit for a new umount bug.

    Andy> Fortunately this one isn't terribly serious, but it might be
    Andy> usable for more than just DoS if some daemon reacts poorly to
    Andy> being unable to write to the filesystem.

    Andy> http://thread.gmane.org/gmane.linux.kernel.stable/109312

Hmm, what damage is this supposed to do? I get (3.12.29):

ql-front-t:/dev/pts# /root/remount-exploit /dev
remount_ro, a DoS by Andy Lutomirski
remount-exploit: umount: Device or resource busy

Maybe you should specify what versions are supposed to be vulnerable

-- 
Roland

-------
http://www.q-leap.com / http://qlustar.com
          --- HPC / Storage / Cloud Linux Cluster OS ---

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.