Comment to the article nails it...
|
Author | Content |
---|---|
JaseP Feb 09, 2011 6:21 PM EDT |
The one comment to the article nails it. This is not a "Linux" vulnerability, it's an evince-thumbnailer vulnerability. You wouldn't get anywhere with this exploit on a server or even on a patched/locked-down desktop. And, there's no evidence that the exploit could be used to gain root authority, either. In other words, it'd be dumb luck if a cracker could use it to access the user account of a Linux desktop. |
Jeff91 Feb 09, 2011 6:46 PM EDT |
Couldn't have said it better myself JaseP ~Jeff |
tracyanne Feb 09, 2011 8:18 PM EDT |
The following makes it even more clear USN-1035-1: Evince vulnerabilitiesQuoting:The problem can be corrected by upgrading your system to the following package versions: In the demonstration Larimer: Quoting:also disabled the Address Space Layout Randomisation (ASLR) and AppArmor security mechanisms. |
gus3 Feb 09, 2011 8:39 PM EDT |
So it could be taken as a win for ASLR and/or AppArmor. Yay for Open Source! |
JaseP Feb 10, 2011 10:37 AM EDT |
It, again, is another example of a "clean room" malware exploit. This wouldn't work in the wild. So, a Linux based system COULD be vulnerable, if one were rely on unpatched add-ons & disable the standard security profiles that keep them in check... Hmmm, that, as opposed to just USING an M$ system that isn't locked down like Fort Knox. Yeah, I'd say casual Linux users are just as at risk as Windozers (where is the sarcasm on/off function on the comment tool???). |
tracyanne Feb 10, 2011 5:00 PM EDT |
Not that anyone should become complacent. |
JaseP Feb 10, 2011 7:06 PM EDT |
Quoting: Not that anyone should become complacent. No, but there's a difference between being complacent & being an apologist for an OS that's "defective by design," by trying to sensationalize a jury-rigged "experiment" for the purpose of weakening the competition. Maybe that wasn't the intent of the presenter, but it sure seemed like that was the hidden message in the article. |
Posting in this forum is limited to members of the group: [ForumMods, SITEADMINS, MEMBERS.]
Becoming a member of LXer is easy and free. Join Us!