[VulnWatch] Linux 2.4 kernel ioperm vuln *is* for 2.4

From: Rain Forest Puppy (rfp_at_vulnwatch.org)
Date: 05/22/03

  • Next message: iDEFENSE Labs: "[VulnWatch] iDEFENSE Security Advisory 05.22.03: Authentication Bypass in iisPROTECT"
    Date: Thu, 22 May 2003 19:57:56 +0000 (GMT)
    To: vulnwatch@vulnwatch.org
    
    

    We've received a few emails asking to clarify if the ioperm bug was for
    2.5 (like it mentioned in the referenced post), or 2.4 like I mentioned in
    the title.

    Red Hat and EnGarde have released advisories and updated 2.4 kernels with
    ioperm patches. CVE has also entered it as CAN-2003-0246, although it is
    sourced from the Red Hat and EnGarde advisories. That leads to conclude
    it's a bug in 2.4; otherwise what the hell are Red Hat and EnGarde
    updating/patching?

    - rfp


  • Next message: iDEFENSE Labs: "[VulnWatch] iDEFENSE Security Advisory 05.22.03: Authentication Bypass in iisPROTECT"