Update your Ubuntu Installs!
#21
Posted 20 September 2010 - 09:06 PM
http://bugs.centos.o...iew.php?id=4518
Instructions on how to migrate to the testing kernel module - my question aside from that, is the kernel something VPS.NET needs to adjust for use in their cloud platform? (still kinda new here)
#22
Posted 21 September 2010 - 08:16 AM
Is there a patch available for Ubuntu 8.04 LTS 64-bit?
Thanks.
#23
Posted 21 September 2010 - 08:21 AM
tn1 said:
Is there a patch available for Ubuntu 8.04 LTS 64-bit?
Thanks.
I haven't tried it yet but there is this workaround
echo ':32bits:M:0:x7fELFx01::/bin/echo:' > /proc/sys/fs/binfmt_misc/register
http://isc.sans.edu/...ml?storyid=9574
#24
Posted 21 September 2010 - 08:34 AM
#25
Posted 21 September 2010 - 09:39 AM
TrevC said:
they can get in anyway they can escalate code, so if they can upload compromised php or js and trigger it from a cron they can technically get the root access
that said if you are a shared host yes you should worry/be vigilant
but if you know exactly who has access to your server you are most likely not needing to panic at this stage
#26
Posted 21 September 2010 - 02:29 PM
Redhat released updated kernels: http://rhn.redhat.co...-2010-0704.html
expect centos ones to be built and ready as soon as they can get them distributed to all the mirrors i get
#27
Posted 21 September 2010 - 06:05 PM
Quote
Came right up on mine.
Update:
Grabbed the URL from the main repo:
http://mirror.centos....el5.x86_64.rpm
Just in case anyone wants to grab it manually if your YUM isn't that tasty yet. :)
This post has been edited by mrcbrown: 21 September 2010 - 06:11 PM
#28
Posted 21 September 2010 - 09:22 PM
#29
Posted 21 September 2010 - 09:42 PM
Jon_ said:
Do:
yum update
(as root) and it should update kernel-xen - mine went flawlessly after reboot.
#30
Posted 21 September 2010 - 09:43 PM
the xen at the ending is because VPS.NET HVs apparently run the Xen hypervisor http://www.xen.org/
#31
Posted 22 September 2010 - 01:06 PM
anthonysomerset said:
There's two exploit. One for ALL KERNEL 2.6. This one allow local root escalation. The other one does not affect RHEL5/CentOS5 (that is maybe why Red Had have been slower to get a patch).
CVE-2010-3301:
http://git.kernel.or...876c484849a74de
http://git.kernel.or...6492063030b55ac
CVE-2010-3081 (this one affects them all):
http://git.kernel.or...782d27a79a81ea6

Help
This topic is locked












