|
BugTraq
Linux kernel ELF core dump privilege elevation May 11 2005 11:08AM Paul Starzetz (ihaquer isec pl) (4 replies) Re: Linux kernel ELF core dump privilege elevation May 12 2005 01:46AM antoine (antoine nagafix co uk) (1 replies) Re: Linux kernel ELF core dump privilege elevation May 13 2005 10:10AM Pedro Venda (pjvenda arrakis dhis org) Re: Linux kernel ELF core dump privilege elevation (kernel module workaround) May 12 2005 12:29AM Andrew Griffiths (andrewg felinemenace org) (1 replies) Re: Linux kernel ELF core dump privilege elevation (kernel module workaround) May 12 2005 10:31PM chris (fool dfw net) Re: Linux kernel ELF core dump privilege elevation May 11 2005 07:34PM Bruno Lustosa (bruno lists gmail com) (1 replies) Re: Linux kernel ELF core dump privilege elevation May 12 2005 05:52PM codeQ (newsclient teamq info) Re: Linux kernel ELF core dump privilege elevation May 11 2005 06:12PM Greg KH (gregkh suse de) (2 replies) Re: Linux kernel ELF core dump privilege elevation May 11 2005 09:51PM Paul Starzetz (ihaquer isec pl) |
|
Privacy Statement |
> On Wed, May 11, 2005 at 01:08:56PM +0200, Paul Starzetz wrote:
> > Hi,
> >
> > since it became clear from the discussion in January about the uselib()
> > vulnerability, that the Linux community prefers full, non-embargoed
> > disclosure of kernel bugs, I release full details right now. However to
> > follows at least some of the responsable disclosure rules, no exploit code will be
> > released. Instead, only a proof-of-concept code is released to demonstrate
> > the vulnerability.
>
> <snip>
>
> And here's a patch for 2.6 that is completly untested. I'll work on
> testing it today and if it works, we will release a new 2.6.11.y release
> with this fix in it.
>
> thanks,
>
> greg k-h
>
>
> Subject: possibly fix Linux kernel ELF core dump privilege elevation
>
> As noted by Paul Starzetz
>
> references CAN-something-I-need-to-go-look-up...
CAN-2005-1263 is the correct one. Sorry for being lazy and not looking
it up right away.
thanks,
greg k-h
[ reply ]