[LUGOS] Hitro krpat jedra! (Re: syslogd sporočila na vse konzole)

Žiga Böhm ziga.boehm at vseved.net
Tue Apr 15 17:01:37 CEST 2003


spodaj pripenjam izvirno objavo alana coxa (vendar brez popravka), za vse 
tiste, ki so omenjeno luknjo do sedaj spregledali ali pa bi se radi kakorkoli 
drugace "utrdili" v nj. poznavanju... ;-)

lp,
z.b.

--
List:     linux-kernel
Subject:  Ptrace hole / Linux 2.2.25
From:     Alan Cox <alan () redhat ! com>
Date:     2003-03-17 16:04:35
[Download message RAW]

Vulnerability: CAN-2003-0127

The Linux 2.2 and Linux 2.4 kernels have a flaw in ptrace. This hole allows
local users to obtain full privileges. Remote exploitation of this hole is
not possible. Linux 2.5 is not believed to be vulnerable.

Linux 2.2.25 has been released to correct Linux 2.2. It contains no other
changes. The bug fixes that would have been in 2.2.5pre1 will now appear in
2.2.26pre1. The patch will apply directly to most older 2.2 releases.

A patch for Linux 2.4.20/Linux 2.4.21pre is attached. The patch also
subtly changes the PR_SET_DUMPABLE prctl. We believe this is neccessary and 
that it will not affect any software. The functionality change is specific 
to unusual debugging situations.

We would like to thank Andrzej Szombierski who found the problem, and
wrote an initial patch. Seth Arnold cleaned up the 2.2 change. Arjan van
de Ven and Ben LaHaise identified additional problems with the original 
fix.

Alan

Dne torek 15. aprila 2003 16:12 je Boris Sagadin napisal(a):
| Spremenil vsa root gesla? :) Script kiddie prve klase. Ptrace luknjo se
| lahko izkoristi le lokalno, torej je potrebno najprej priti v sistem na kak
| drug način.
|
| ----- Original Message -----
| From: "Janko Mivsek" <janko.mivsek at eranova.si>
| To: <lugos-list at lugos.si>
| Sent: Tuesday, April 15, 2003 3:20 PM
| Subject: [LUGOS] Hitro krpat jedra! (Re: syslogd sporočila na vse konzole)
|
| > Živjo,
| >
| > Kaže, da včeraj nisem bil edini napaden. Torej, iz znanega ISP-ja tudi
| > poročajo o napadu, ki je po njihovem mnenju izkoristil nedavno odkrito
| > luknjo v Linux jedru. Opazili so ga po tem, da so bila sprememnjena vsa
| > root gesla. V mojem primeru so bili zamenjani su, pstree, syslogd in še
| > nekateri.




More information about the lugos-list mailing list