Forum Moderators: bakedjake

Message Too Old, No Replies

New kernel vulnerability

Cve-2014-9322

         

not2easy

6:46 pm on Dec 18, 2014 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



A note from my new host tells me there is a
severe kernel vulnerability that has just been announced: CVE-2014-9322. It is paramount to your server's security that this update be applied immediately, because it allows an unprivileged user with access to your server the ability to obtain root privileges within your server.


They've already applied the patch. I just wanted to share this information. A good place for more information: [web.nvd.nist.gov...]

lammert

11:31 am on Dec 21, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



As far as I can see it you will be only vulnerable for this bug if your server allows shell access to other users. If these users execute a specially crafted executable, the vulnerability will be triggered. This might be a problem for people on shared hosting, but less for those who operate a dedicated server.