openSUSE kernels on 1&1 root servers may be out of date
IT services provider Markus Manze stumbled on the problem when compiling an overview of Linux distributions and the null pointer dereference bugs they contain. According to Manke's German language report on the problem, in view of the availability of exploits, an unpatched kernel turns security vulnerabilities in other applications, such as web servers, PHP applications and other network services, into potentially system-compromising vulnerabilities. Furthermore, the mmap_min_addr system variable, which is able to frustrate NPD exploits, is set to 0 in openSUSE 11.0.
The link for this article located at H Security is no longer available.