The brk() vulnerability
Posted Dec 2, 2003 19:04 UTC (Tue) by
JoeBuck (subscriber, #2330)
Parent article:
The brk() vulnerability
The problem with doing kernel maintainance in public is that the bad guys are watching. Every commit to the source control system that fixes a flaw is an opportunity for a cracker to ponder whether unpatched systems can be exploited. I fear that publicity surrounding this particular exploit will alert others to this way of finding new cracks. Of course, the kernel maintainers are already aware of this possibility, so they will be more cautious when they are conscious that they are fixing a security hole. But any missing integrity check might make an exploit possible.
(
Log in to post comments)