Re: Kernel exploit in brk() function.

Ricardo Barberis <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Dattatec.com
Message-ID <[email protected]>
Christophe Devine wrote:

> Sam Halliday <[email protected]> wrote:
> 
>> > bash-2.05a$ gcc -static hatorihanzo.c
>> > bash-2.05a$ ./a.out
>> > sh-2.05a# id
>> > uid=0(root) gid=0(root)
> 
>> hmm... strangely it fails for me on a 2.4.22 kernel; i thought it was
>> still vulnerable?
>> 
>>   gcc -static hatorihanzo.c
>>   ./a.out
>>   [-] Unable to unmap stack: Invalid argument
>> 
>> but, it did work on a Redhat 7.2 2.4.20-19.7 kernel.
> 
> Yeah, some friend of mine noticed that too. It looks like on most
> distros like Debian the exploit works; but it appears to fail when
> compiled with recent versions of gcc/binutils.

Just a heads up, the Slackware 9.1 with 2.4.22 I have in my office PC is
vulnerable.
However, in our servers we have a RH 7.2 with 2.4.18-27.7, a RH 7.3 with
2.4.20-18.7 and another with 2.4.18-27.7.xsmp which are NOT, and we
have a RH with a vanilla 2.4.22 compiled by one of our guys and also is
NOT vulnerable (I can keep posting about our servers if you want).

Now a question, does RH's gcc-2.96 have anything to do about this?

Cheers,
-- 
Ricardo Barberis
Usuario Linux Nº 250625:           http://counter.li.org
Usuario LFS Nº 5121:               http://www.linuxfromscratch.org
LFS en castellano:                 http://www.lfs-es.org
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.