bk99.de entertain the web since 1997

Blog 2006

16 posts

Projects, Linux, networks, systems, finds and internet standards from 2006.

New Linux kernels close security holes

In August 2006 new Linux kernels of the 2.4.33, 2.6.16 and 2.6.17 series appeared that closed security holes. A bug in the SCTP function sctp_make_abort_user allowed logged-in attackers to execute code with higher privileges. A UDF bug crashed the system and had not yet been fixed in 2.4.33.

Read the full post

IBM closes security holes in Informix database

In August 2006 IBM published updates for several holes in Informix Dynamic Server that NGSSoftware had already reported in January 2005. Functions such as LOTOFILE and SET DEBUG FILE could be used to write arbitrary files, and there were also numerous buffer overflows in SQL functions and at protocol level. One cause of the protocol bugs was the C function getname(), which copies strings unchecked like strcpy().

Read the full post

Economical Linux server with 16 MIPS64 processor cores

In 2006 Movidis presented the Revolution x16 server with a Cavium Octeon processor, whose 16 MIPS64 cores were to draw less than 30 watts together. The platform offered eight gigabit ports, up to 8 GByte of RAM, a SAS/SATA host adapter and Linux with kernel 2.6.13.5 in NAND flash. The cores only had integer units, but in return accelerators for crypto, compression and TCP.

Read the full post

AppArmor and SELinux compared

Ralf Spenneberg compares AppArmor and SELinux as mandatory access control systems and shows differences in model, configuration and administration. A less powerful model can be more secure in practice if operators actually maintain it. Additional control only helps if policies match the real behaviour of applications.

Read the full post

OpenVZ to be brought into the Linux kernel

According to CNet, in 2006 SWsoft wanted to bring its free virtualisation technology OpenVZ into the official Linux kernel, with support from Red Hat. OpenVZ sets up virtual private servers that share one kernel and are therefore very efficient. At the same time Red Hat was pushing the competing technology Xen and announced Xen virtualisation for the next RHEL.

Read the full post

Linux also vulnerable to the WMF security hole through Wine

In January 2006 the WMF hole, through which manipulated image files executed code under Windows, also affected Wine, Cedega and CrossOver Office. According to HD Moore, author of the proof of concept, the complete metafile API had been recreated in Wine, including the bug. Not only Windows code but also native shellcode could be executed, and Marcus Meissner of SUSE supplied a patch.

Read the full post

Linux kernel 2.6.15 with improved NTFS support

In January 2006, after seven release candidates, Linus Torvalds released kernel 2.6.15. It brought changes to software RAID, an NTFS driver with limited write support and initial support for the Linksys NSLU2 NAS. The function vm_insert_page() was controversial, as Torvalds also made it available to Nvidia’s proprietary drivers.

Read the full post