root initramfs shell vuln - Raspberry Pi Forums


hi,
have not been able reproduce on raspbian pi vulnerability root initramfs shell can achieved on locked linux host 70 second keypress.

can confirm whether raspbian affected?

are running encrypted file system? if not there no vulnerability.

http://hmarco.org/bugs/cve-2016-4484/cv ... shell.html
http://www.theregister.co.uk/2016/11/16 ... _a_minute/ (read comments in particular article pretty vague on details).
reading articles if can shell, you're faced encrypted file system , no keys it.

, there old mantra if attacker can physical access press enter 70 seconds, you're system hosed anyway.
edit: should have read full cve myself before posting - reference adage physical access game on :o


raspberrypi



Comments