OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Linux 2.4.26-ow1, 2.0.40-ow1; new Owl ISO; Owl 1.1-stable

From: Steve Bremer (stevebnebcoinc.com)
Date: Wed Apr 21 2004 - 10:25:07 CDT


In response to Tomasz's question, I don't see anything that would
prevent this vulnerability in the Openwall Linux kernel patch. However,
and I'm still trying to find an answer to this myself, it may be that a
kernel that is compiled without CONFIG_IP_MULTICAST is not vulnerable.
I've been trying to poke around in the code to find an answer, but
haven't had much luck finding an answer so far (I'm not a kernel/systems
programmer by a long shot).

Steve Bremer
NEBCO, Inc.
Systems & Security Administrator