Red Hat Bugzilla – Bug 5002
Mars-Nwe security vulnerability
Last modified: 2008-05-01 11:37:51 EDT
I'm not too sure that redhat 6 is vulnerable to this but you
might want to check it out. mars-new package is/has a
boundary condition error..a local exploitable buffer
overflow. Its a root exploit. All versions upto and
including 0.99 (redhat 6?) are believed to be vulnerable to
this. Also wanted to report that anaconda (redhat 6.1's
installer) seems to crash and reboot the machine when it
cant detect the video card (i.e. it cant load the VGA_16
server). not sure where to put that one. Also you might want
to check or change the 6.1 mars-nwe too.
Actually, the code that calls system (with the buffer
overflow) is never used.
Fixed in the errata release.