Re: Pentium DEATH in user-mode

Oliver Xymoron (oxymoron@waste.org)
Sun, 9 Nov 1997 12:28:14 -0600 (CST)


On Sat, 8 Nov 1997, Richard B. Johnson wrote:

> If your pentium is used as a file-server or something in which a
> user doesn't log in, you will have no problem. Just rename the gcc
> compiler so someone can't write code on your system.

Note that this bug means ANY buffer overflow bug, even on non-setuid apps,
is now an entry point for an attacker to crash your machine. Got users on
your system who wrote their own CGI apps in C? Ouch. Let's make that
non-executable stack patch part of the mainstream kernel.

--
 "Love the dolphins," she advised him. "Write by W.A.S.T.E.."