Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Qualys Security Advisory – Linux PIE/stack Corruption (CVE-2017-1000253) (seclists.org)
4 points by _vvdf on Sept 26, 2017 | hide | past | favorite | 1 comment


This is over particular interest because this is a local privilege escalation from 2015 that several major Linux vendors (RHEL and Centos) have failed to apply! See seclist post linked above for details.

> Most notably, all versions of CentOS 7 before 1708 (released on September 13, 2017), all versions of Red Hat Enterprise Linux 7 before 7.4 (released on August 1, 2017), and all versions of CentOS 6 and Red Hat Enterprise Linux 6 are exploitable.

Wow.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: