Exploits Emerge For Linux Privilege Escalation Flaw
angry tapir writes "Linux vendors are rushing to patch a privilege escalation vulnerability in the Linux kernel that can be exploited by local attackers to gain root access on the system. The vulnerability, which is identified as CVE-2012-0056, was discovered by Jüri Aedla and is caused by a failure of the Linux kernel to properly restrict access to the '/proc//mem' file."
If someone is in a position to run a local exploit, aren't you pretty much fucked anyways?
Again, you don't know what security through obscurity means. If the access to the code or other design that implements the security breaks it, then that is security through obscurity. All security relies on a secret known by one party, but unknown to others. This has absolutely nothing to do with security by obscurity.
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun