Glibc Pointer guarding weakness

Hector Marco-Gisbert <[email protected]>
Newsgroups gmane.comp.security.fulldisclosure,gmane.comp.security.news.securitytracker,gmane.comp.security.bugtraq
Message-ID <[email protected]>
Hello,

A weakness in the dynamic loader have been found, Glibc prior to 2.22.90 
are affected. The issue is that the LD_POINTER_GUARD in the environment 
is not sanitized allowing local attackers easily to bypass the pointer 
guarding protection on set-user-ID and set-group-ID programs.


Details and PoC at:
http://hmarco.org/bugs/glibc_ptr_mangle_weakness.html


A patch is already sent to Glibc maintainers. This issue is similar to 
http://hmarco.org/bugs/CVE-2013-4788.html but now affect to dynamic 
linked applications.


-- 
Hector Marco-Gisbert @ http://hmarco.org/
Cyber Security Researcher @ http://cybersecurity.upv.es
Universitat Politècnica de València (Spain)

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.