|
BugTraq
Linux kernel ELF core dump privilege elevation May 11 2005 11:08AM Paul Starzetz (ihaquer isec pl) (4 replies) Re: Linux kernel ELF core dump privilege elevation May 12 2005 01:46AM antoine (antoine nagafix co uk) (1 replies) Re: Linux kernel ELF core dump privilege elevation May 13 2005 10:10AM Pedro Venda (pjvenda arrakis dhis org) Re: Linux kernel ELF core dump privilege elevation (kernel module workaround) May 12 2005 12:29AM Andrew Griffiths (andrewg felinemenace org) (1 replies) Re: Linux kernel ELF core dump privilege elevation (kernel module workaround) May 12 2005 10:31PM chris (fool dfw net) Re: Linux kernel ELF core dump privilege elevation May 11 2005 06:12PM Greg KH (gregkh suse de) (2 replies) Re: Linux kernel ELF core dump privilege elevation May 11 2005 09:51PM Paul Starzetz (ihaquer isec pl) |
|
Privacy Statement |
> since it became clear from the discussion in January about the uselib()
> vulnerability, that the Linux community prefers full, non-embargoed
> disclosure of kernel bugs, I release full details right now. However to
> follows at least some of the responsable disclosure rules, no exploit code will be
> released. Instead, only a proof-of-concept code is released to demonstrate
> the vulnerability.
Paul, I was unable to make it work on my amd64.
Running Gentoo on kernel 2.6.11.
This was the output:
[+] Compiling...elfcd1.c: In function `main':
elfcd1.c:48: warning: implicit declaration of function `strlen'
elfcd1.c:54: warning: implicit declaration of function `memset'
elfcd1.c:60: warning: implicit declaration of function `strcmp'
/usr/lib/gcc/x86_64-pc-linux-gnu/3.4.3/../../../../x86_64-pc-linux-gnu/b
in/ld:
warning: i386:x86-64 architecture of input file `/tmp/ccSCdKeo.o' is
incompatible with i386 output
[+] ./elfcd1 argv_start=0x7ffffffff451 argv_end=0x7ffffffff459 ESP: 0xfffff0e0
[+] phase 1
[+] AAAA argv_start=0x7fffffff6fea argv_end=0x7fffffff6fee ESP: 0xffff6de0
[+] phase 2, <RET> to crash Segmentation fault (core dumped)
--
Bruno Lustosa, aka Lofofora | Email: bruno (at) lustosa (dot) net [email concealed]
Network Administrator/Web Programmer | ICQ: 1406477
Rio de Janeiro - Brazil |
[ reply ]