This post is getting very few responses although it looks serious. Any response from Stephen,Rickenbacherus,etc ? I am really concerned about this.
This post is getting very few responses although it looks serious. Any response from Stephen,Rickenbacherus,etc ? I am really concerned about this.
No-one has sent it to the debian-knoppix mailing list, however, it is a local exploit.
Now if you're worried about a local exploit, I take it you have your computer in a locked safe with no physical access to it?
Additionally, I don't see a .qt directory in /tmp/ . Do you have one?
What is a Local Exploit?
It means you must already have an account on your computer before you can exploit it.
So does it mean this security problem is not severe?
Please make this clear.
Thanks!
I think the post got the response it deserved I have the last two version installed on a spare drive I use for testing and could find no such file in either.
And to be perfectly clear on the local expliot a person must have physical access to your machine and be able to login to the computer. The only totaly secure computer is one kept under lock and key that only you have access to and with no connection to any network.
I was concerned because I do have those files both on root's home and my home-the is the .qt directory with the files mentioned in that alert. I have version 0606.
Would it be safe to delete the directory? I have no idea if it relates to the qt programs.
I've logged into my nephew's computer which I have put the 06-06 version on a well and the file is not here either that being said it is only a directory in the /tmp directory so remove it if you feel that uncomfortable with it being there as was stated above the only way someone could use the exploit ( if it is actually one this has yet to be confirmed) would be to have access to your computer.
Thanks Stephen for replying and please pardon my seemingly paranoid reaction to this. One of the reasons why I am shifting to Linux is the frequent security problems and various viri which seem to plague windows systems. At one time my pc and the office pc was infected with 10 viri which fortunately norton was able to catch. And now this.
BTW, the .qt directory in my pc is NOT in the /tmp. It is one of the hidden directory on the /home/user. In this case, does this relate to the alert or it is not affected ,being not in the /tmp directory?
The .qt files in the other directories are fine and safe. Don't remove them!
If you're still feeling paranoid (and it's not such a bad thing!) you might like to install a firewall and look for Linux security articles on the internet (Google will chuck up plenty).
But it's worth mentioning that the best security strategy is to simply back up your data.

Gigabyte 4U AI Server 10x Nvidia GPU 2x Xeon Gold 6150 36 Core 2.7GHz DDR4 RAM
$1625.00
Dell EMC PowerEdge R440 Xeon silver 4215 2.5GHz 16 GB ram 2x 550W PSU No HDD
$275.00
867959-B21 HPE ProLiant DL360 G10 CTO Server W/ 2x 865414-B21 1x 840140-001
$245.00
Dell PowerEdge R240 Intel Xeon E-2224 3.50GHz 8GB DDR4 ECC NO HDD 250W
$285.97
Dell PowerEdge R730 8Bay 64Gb 1x80Gb SSD 4x900Gb SAS 2x12c v4CPU 1100ws, 2GPUCbl
$660.00
Dell PowerEdge R730XD 28 Core Server 2X Xeon E5-2680 V4 H730 32GB RAM No HDD
$378.93
Dell PowerEdge C4130 1U AI GPU Server | 2x E5-2690 v3 | 64gb Ram | 2x 1600W
$524.99
Dell PowerEdge C4130 1U AI GPU Server | 2x E5-2680 v3 | 32gb Ram | 2x 1600W
$409.99
Dell PowerEdge FX2s + 8x FC430 Blades 16x E5-2630v4 160 Cores Rails No PSU/RAM
$699.00
Dell Poweredge R630 2x Intel Xeon E5-2650 v4 32GB RAM No Drives/OS Server
$292.50