* Status of IEEE1394 vulnerability in 2.4
@ 2004-07-21 0:32 Moritz Muehlenhoff
2004-07-21 1:26 ` Ben Collins
0 siblings, 1 reply; 2+ messages in thread
From: Moritz Muehlenhoff @ 2004-07-21 0:32 UTC (permalink / raw)
To: linux-kernel
Hi,
what's the status of the IEEE 1394 vulnerability wrt
kernel 2.4? [1]
Will it be fixed in 2.4.27? rc3 is two weeks old and
there haven't been bitkeeper snapshots since April.
Cheers,
Moritz
Footnotes:
[1] http://www.osvdb.org/displayvuln.php?osvdb_id=7253
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: Status of IEEE1394 vulnerability in 2.4
2004-07-21 0:32 Status of IEEE1394 vulnerability in 2.4 Moritz Muehlenhoff
@ 2004-07-21 1:26 ` Ben Collins
0 siblings, 0 replies; 2+ messages in thread
From: Ben Collins @ 2004-07-21 1:26 UTC (permalink / raw)
To: Moritz Muehlenhoff; +Cc: linux-kernel
On Wed, Jul 21, 2004 at 02:32:57AM +0200, Moritz Muehlenhoff wrote:
> Hi,
> what's the status of the IEEE 1394 vulnerability wrt
> kernel 2.4? [1]
> Will it be fixed in 2.4.27? rc3 is two weeks old and
> there haven't been bitkeeper snapshots since April.
I have yet to fix them. Note that they are NOT as serious as described.
One requires a local user to have access to the devices. Generally this
isn't the default case. The other one requires maliciously changed
firmware in an external device. Not too many people have the know-how and
desire to do this, just to crash your system (they would have better luck
just beating your box with a hammer).
The other bug about allocating huge amounts of memory is just plain wrong,
and is not a bug. It cannot happen.
I'll be fixing things this weekend.
--
Debian - http://www.debian.org/
Linux 1394 - http://www.linux1394.org/
Subversion - http://subversion.tigris.org/
WatchGuard - http://www.watchguard.com/
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2004-07-21 2:15 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2004-07-21 0:32 Status of IEEE1394 vulnerability in 2.4 Moritz Muehlenhoff
2004-07-21 1:26 ` Ben Collins
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®