OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Dailydave] Remote kernel bug in SCTP?

From: Nicolas RUFF (nruffsecurity-labs.org)
Date: Sat Mar 14 2009 - 02:55:37 CDT


> Did everyone else already know about this bug? So you connect to an SCTP
> endpoint, then send a packet to overwrite arbitrary kernel data? That'd
> be cool.

If you can read French (and I know some people in your team does ;), you
will find more information about this bug here:

http://esec.fr.sogeti.com/blog/index.php?2009/01/08/48-correction-silencieuse-d-une-vulnerabilite-dans-le-noyau-linux

Regards,
- Nicolas RUFF
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave