BugTraq
rPSA-2006-0122-2 kernel Jul 13 2006 08:28PM
Justin M. Forbes (jmforbes rpath com) (1 replies)
rPath Security Advisory: 2006-0122-2
Published: 2006-07-07
Updated:
2006-07-13 Upgraded to Critical status with additional information
Products: rPath Linux 1
Rating: Critical
Exposure Level Classification:
Local Root Deterministic Privilege Escalation
Updated Versions:
kernel=/conary.rpath.com@rpl:devel//1/2.6.16.24-0.1-1

References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2451
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2934
https://issues.rpath.com/browse/RPL-488

Description:
Previous versions of the kernel package have two specific
vulnerablities that are addressed in this version.

The first vulnerability allows any local user to fill up file
systems by causing core dumps to write to directories to which
they do not have write access permissions, and on most systems
(including any system that provides a generally-accessible "cron"
or "at" service) to escalate to run arbitrary code as the root user.
An exploit for this privilege escalation vulnerability is
publically available and in active use.

The second vulnerability applies only to systems using the SCTP
protocol, which is not enabled by default, and the tools required
to configure it (lksctp-tools) are not included in rPath Linux.
This vulnerability, which cannot apply to systems without
lksctp-tools installed, enables a remote denial of service attack
in which specially-crafted packets can crash the system.

A system reboot is required to make the update to resolve these
vulnerabilities effective. rPath strongly recommends that all
users apply this update.

[ reply ]
Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround Jul 14 2006 02:50PM
Caveo Internet BV - Security (security caveo nl) (3 replies)
Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround Jul 14 2006 07:08PM
Hugo van der Kooij (hvdkooij vanderkooij org)
Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround Jul 14 2006 06:36PM
Lukasz Trabinski (lukasz wsisiz edu pl) (1 replies)
Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround Jul 16 2006 10:11AM
Michal Zalewski (lcamtuf dione ids pl)
Re: Linux Kernel 2.6.x PRCTL Core Dump Handling -- Simple workaround Jul 14 2006 05:32PM
Michael Shigorin (mike osdn org ua)


 

Privacy Statement
Copyright 2010, SecurityFocus