Section: .. / linux / security /
| /// File Name: |
linux-2.2.18-ow4.tar.gz |
Description:
|
The Secure-Linux patch adds a few security features to the kernel which, while not a complete method of protection, will stop most of the 'cookbook' buffer overflow exploits cold. It also adds the option of restricting the use of symlinks and named pipes in +t (temp) directories which fixes most tmp-race exploits as well. It can also add a little bit more privacy to the system by restricting access to parts of /proc to root so that users may not see who else is logged on or what they're doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction, and privileged IP aliases for kernel 2.0.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | A fix for the recently announced execve(2)/ptrace(2) race condition vulnerability in the Linux kernel. Readme available | | File Size: | 25353 | | Last Modified: | Feb 10 17:26:26 2001 |
| MD5 Checksum: | 3778930319d1d3040f9fc598005cbad2 |
|
| /// File Name: |
linux-2.2.18-stealth1.diff |
Description:
|
The Stealth Kernel Patch for Linux v2.2.18 makes the linux kernel discard the packets that many OS detection tools use to query the TCP/IP stack. Includes logging of the dropped query packets and packets with bogus flags. Does a very good job of confusing nmap and queso.
| | Author: | Sean Trifero | | Homepage: | http://www.innu.org/~sean | | Changes: | Fixed 2.2->2.4 connectivity problems and ported to kernel 2.2.18. | | File Size: | 17836 | | Last Modified: | Dec 20 16:03:03 2000 |
| MD5 Checksum: | a0a77e93859e7bd2b2dba329fc459516 |
|
| /// File Name: |
linux-2.2.19-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Updated to Linux 2.2.19, which contains security fixes not included in older versions of the patch. Readme available | | File Size: | 24414 | | Last Modified: | Mar 28 20:28:48 2001 |
| MD5 Checksum: | 944a6566a057ca99a3b1575e67db8aea |
|
| /// File Name: |
linux-2.2.19-ow3.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Fixes the possible local root vulnerability discovered recently in kernel v2.2.19. Readme available | | File Size: | 27976 | | Last Modified: | Oct 20 04:40:42 2001 |
| MD5 Checksum: | 26fd536156c5f44070817cd512e42fa0 |
|
| /// File Name: |
linux-2.2.19-ow4.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Fixes two Linux kernel vulnerabilities. A non-security symbol export issue was fixed and support for ELF executables was put into a separate configuration option. Readme available | | File Size: | 28920 | | Last Modified: | Oct 23 12:27:36 2001 |
| MD5 Checksum: | 07a55b30cb52a8646d42037965695df7 |
|
| /// File Name: |
linux-2.2.19-stealth1.diff |
Description:
|
The Stealth Kernel Patch for Linux v2.2.19 makes the linux kernel discard the packets that many OS detection tools use to query the TCP/IP stack. Includes logging of the dropped query packets and packets with bogus flags. Does a very good job of confusing nmap and queso.
| | Author: | Sean Trifero | | Homepage: | http://www.innu.org/~sean | | Changes: | Now works with kernel v2.2.19. | | File Size: | 17837 | | Last Modified: | Apr 7 04:05:11 2001 |
| MD5 Checksum: | 29d386c15f8bd808ae57e44d43a61afc |
|
| /// File Name: |
linux-2.2.20-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Ported to 2.2.0. This version moves even more of the support for combined ELF/a.out setups under the configuration option introduced with 2.2.19-ow4. Readme available | | File Size: | 28332 | | Last Modified: | Nov 6 01:53:16 2001 |
| MD5 Checksum: | 1567d99da210896db17c3eee79f49969 |
|
| /// File Name: |
linux-2.2.20-ow2.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Fixed an x86-specific Linux kernel vulnerability where local users could abuse a binary compatibility interface (lcall) to kill processes not belonging to them, including system processes. | | File Size: | 28948 | | Last Modified: | Mar 4 01:15:30 2002 |
| MD5 Checksum: | 789b9b631a3930e3ba765381278d04ea |
|
| /// File Name: |
linux-2.2.20-ow3.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Fixes the recent zlib (PPP/IrDA Deflate compression) problem and added fixes for two Alpha-specific bugs introduced in Linux 2.2.20. | | File Size: | 29267 | | Last Modified: | Apr 6 02:41:39 2002 |
| MD5 Checksum: | 021cc007b503daa3cad2bb0ef35c4fb5 |
|
| /// File Name: |
linux-2.2.21-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Updated for Linux 2.2.21. Permissions on /proc entries have been changed to be consistent with Linux 2.4.18-ow0, and the getcwd(2) instance of the d_path() truncation problem and the fsuid/fsgid handling inconsistency have been fixed. | | File Size: | 29327 | | Last Modified: | Jun 3 01:44:01 2002 |
| MD5 Checksum: | 0b846c829eae6276c57357fe72c3d180 |
|
| /// File Name: |
linux-2.2.21-ow2.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Added many security fixes for issues with the Linux kernel. | | File Size: | 43184 | | Last Modified: | Sep 11 03:17:15 2002 |
| MD5 Checksum: | f84249514f5ae1f7c445955725738174 |
|
| /// File Name: |
linux-2.2.22-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Updated for Kernel v2.2.22. | | File Size: | 27415 | | Last Modified: | Sep 20 12:33:11 2002 |
| MD5 Checksum: | acb8ef1aa99d283e7a9a06fc7ab9a406 |
|
| /// File Name: |
linux-2.2.22-ow2.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Linux 2.2.22-ow2 improves the "lcall" DoS fix for the Linux kernel to cover the NT (Nested Task) flag attack discovered by Christopher Devine. | | File Size: | 27701 | | Last Modified: | Nov 27 01:19:29 2002 |
| MD5 Checksum: | 2db63ab8503cd8a8df7b903e06c0cf0c |
|
| /// File Name: |
linux-2.2.23-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Ported to kernel v2.2.23. | | File Size: | 26894 | | Last Modified: | Dec 5 10:33:49 2002 |
| MD5 Checksum: | cb51cfdd978eba987ca39d09960e17c3 |
|
| /// File Name: |
linux-2.2.25-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Ported to kernel v2.2.25. | | File Size: | 27302 | | Last Modified: | Nov 30 22:49:27 2003 |
| MD5 Checksum: | 0ff48567fc27c329d28965e057c2c8a6 |
|
| /// File Name: |
linux-2.2.26-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Ported to kernel v2.2.26. | | File Size: | 26836 | | Last Modified: | Mar 1 13:26:00 2004 |
| MD5 Checksum: | 55d6ce3e95bfd88632987c170c360aed |
|
| /// File Name: |
linux-2.3.99-pre5-securestack.tar.g..> |
Description:
|
This is the securestackpatch by Openwall, ported for linux 2.3.99-pre5. There are no fancy configuration options, when you use this patch, next time you compile your kernel, the stack will be secure.
| | Author: | Karin | | File Size: | 3719 | | Last Modified: | Apr 22 02:19:10 2000 |
| MD5 Checksum: | 53dd3994657144db59534a01dc45d81a |
|
| /// File Name: |
linux-2.4.23-ow2.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Fixes two newly discovered local root vulnerabilities in the mremap() system call. Ported to kernel v2.4.23. | | File Size: | 31985 | | Last Modified: | Jan 6 01:38:11 2004 |
| MD5 Checksum: | 7e69e67d2eef41504cc8521128e055c0 |
|
| /// File Name: |
linux-2.4.24-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Ported to kernel v2.4.24. Upgrade for users of linux-2.4.23-ow2 is not needed. | | File Size: | 30420 | | Last Modified: | Jan 8 14:43:28 2004 |
| MD5 Checksum: | a2a870b0dbfea6c81542b09c85e00dbc |
|
| /// File Name: |
linux-2.4.26-ow3.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Corrects the access control check in the Linux kernel which previously wrongly allowed any local user to change the group ownership of arbitrary NFS-exported/imported files (CAN-2004-0497). Also adds a workaround for the file offset pointer races (CAN-2004-0415). | | File Size: | 36303 | | Related CVE(s): | CAN-2004-0497, CAN-2004-0415 | | Last Modified: | Aug 10 03:48:46 2004 |
| MD5 Checksum: | a28962d6839f5f2511f28978393407c1 |
|
| /// File Name: |
linux-2.4.27-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | New kernel, new patch. | | File Size: | 33467 | | Last Modified: | Aug 14 13:24:43 2004 |
| MD5 Checksum: | 6eb45801c030877e3123a964552ad840 |
|
| /// File Name: |
linux-2.4.28-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security "hardening" features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | 2.4.28-ow1 fixes a number of security-related bugs, including the local root ELF loader vulnerabilities discovered by Paul Starzetz, a race condition with reads from Unix domain sockets (potential local root), and smbfs support vulnerabilities discovered by Stefan Esser (remote DoS by a malicious smbfs server; potential: remote root by a malicious smbfs server). | | File Size: | 34715 | | Last Modified: | Nov 24 00:04:10 2004 |
| MD5 Checksum: | a17719c83b71c328ef92b53761f3819a |
|
| /// File Name: |
linux-2.4.29-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security hardening features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Adds a number of security fixes, including to the x86/SMP page fault handler and the uselib(2) race conditions, both discovered by Paul Starzetz. | | File Size: | 31342 | | Related CVE(s): | CAN-2004-1235, CAN-2005-0001 | | Last Modified: | Jan 22 15:29:26 2005 |
| MD5 Checksum: | b300f3d45f699f2cdc7bfee417dd4e26 |
|
| /// File Name: |
linux-2.4.30-ow3.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security hardening features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | This version adds a fix to the ELF core dump vulnerability. | | File Size: | 35491 | | Related CVE(s): | CAN-2005-1263 | | Last Modified: | Jun 1 03:19:03 2005 |
| MD5 Checksum: | 15ea2e5b5818c2207eb8026147d168c7 |
|
| /// File Name: |
linux-2.4.31-ow1.tar.gz |
Description:
|
The Openwall Linux kernel patch is a collection of security hardening features for the Linux kernel which can stop most 'cookbook' buffer overflow exploits. The patch can also add more privacy to the system by restricting access to parts of /proc so that users may not see what others are doing. Also tightens down file descriptors 0, 1, and 2, implements process limits and shared memory destruction.
| | Author: | Solar Designer | | Homepage: | http://www.openwall.com/linux | | Changes: | Minimal changes. | | File Size: | 32692 | | Last Modified: | Jun 18 14:32:27 2005 |
| MD5 Checksum: | f37f5b4763a9bf179bb7f5393d413d50 |
|
|
|
|
|