Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 







Current Newswire:

Ultimate Firefox Productivity Tips: For the Geeks.

GoldenDict: A Dictionary Nugget

Would You Like Linux With Your Jello?

Why I Use Linux: Lofton’s Story

Go to Toys 'R Us for your Linux netbook needs

Sun xVM VirtualBox 3.0: Virtual Developer's Delight

Apple Wary of Ogg Theora: No Agreement Yet on HTML5 Video Standard

Freedom is not Free for Countries nor Computer Users

Eyecandy Themes For Ubuntu - Download directly from Synaptic - No More Hassles

Sifting Through Billions and Billions of Bytes




Security Engineer (PA)
Next Step Systems
US-PA-Philadelphia

Justtechjobs.com Post A Job | Post A Resume
:Security issue with MILO/Alpha Linux
Security issue with MILO/Alpha Linux
Feb 6, 1999, 22 :42 UTC (0 Talkback[s]) (2421 reads)

As posted to BUGTRAQ:

                                                    KSR[T] Advisory #009
                                                    Date:  Feb. 5th 1999
                                                    ID #:  NonPrivdHALT

Affected Program:    MILO/Alpha Linux

Operating System(s): Linux (Redhat 5.x)

Summary:             Any local user can cause an Alpha Linux machine to
                     reboot, lock up or become unstable.

Problem Description: During the beta-testing of an instruction set
                     auditor, the KSR[T] team found several instructions
                     that caused an Alpha Linux machine to generate an
                     'Oops' or to reboot/hang.  This involves the call_pal
                     instruction with different immediate arguments.

                     The PALcode currently used in the MILO that comes
                     with Redhat 5.x and below has two additional
                     debugging PAL calls, DBGSTOP (0xAD) and NPHALT
                     (0xBF).  NPHALT is a non-privileged HALT
                     instruction, which brings the machine straight
                     back to the console even from user space.

                     These calls were used during the development of
                     MILO and were not intended for production use.

Notes:               We would like to thank Richard Henderson,
                     Alan Cox for their help with this advisory.

                     Special thanks to Nikita Schmidt for the
                     problem description.

Patch/Fix:           The copies of MILO distributed at
                     ftp://genie.ucd.ie/pub/alpha/milo/milo-latest
                     are not vulnerable to this attack.


No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP