login
Header Space

 
 

root

Patching CVE-2008-0600, Local Root Exploit

February 11, 2008 - 10:23pm
Submitted by Jeremy on February 11, 2008 - 10:23pm.
Linux news

Patches for a much publicized Linux kernel local root exploit were released today as 2.6.24.2, 2.6.23.16, and 2.6.22.18. The latest bug, labeled as CVE-2008-0600, was introduced by the vmsplice() system call and added into the 2.6 kernel in 2.6.17. It is the third in a series of root exploits surrounding the same system call, the two earlier bugs being CVE-2008-0009 and CVE-2008-0010. Easily obtained exploits exist for both the older CVE-2008-0010 which affected the 2.6.23 and 2.6.24 kernels, and the latest CVE-2008-0600, allowing a local non-root user to gain root permissions.

Cedant controlled FreeBSD 6.1 dedicated server with no way to access root account (Plesk Management)

July 14, 2007 - 3:40pm
Submitted by gberz3 on July 14, 2007 - 3:40pm.
FreeBSD

Hi All,

A bit of an odd situation. I recently purchased $99/mth dedicated hardware from Cedant. It is running FreeBSD 6.1. The system seems to have no root user, and no way to access it. All of the following fail:

"su" - FAILS (sorry)
"sudo" - FAILS (command not found)
"passwd root" - FAILS (passwd: permission denied)

speck-geostationary