Re: Kernel exploit in brk() function.

Ricardo Barberis <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Dattatec.com
Message-ID <[email protected]>
Christophe Devine wrote:

> Ricardo Barberis <[email protected]> wrote:
> 
>> However, in our servers we have a RH 7.2 with 2.4.18-27.7, a RH 7.3
>> with 2.4.20-18.7 and another with 2.4.18-27.7.xsmp which are NOT, and
>> we have a RH with a vanilla 2.4.22 compiled by one of our guys and
>> also is NOT vulnerable (I can keep posting about our servers if you
>> want). Now a question, does RH's gcc-2.96 have anything to do about
>> this?
> 
> Possibly, I think it must also depend on the version of binutils; I
> haven't started investigating this problem yet. However you may still
> be vulnerable even if the exploit doesn't seem to work. There's a poc
> code you can use to be 100% sure at:
> http://packetstormsecurity.nl/filedesc/brk_poc.asm.html
> 
> Christophe

Nice piece of code, unfortunately we manage remote servers and I don't
think the boss will like that we might reboot them :-)

About binutils, these are the results of ld -v on the servers I checked
so far:
GNU ld version 2.11.93.0.2 20020207
GNU ld version 2.11.90.0.8 (with BFD 2.11.90.0.8)
GNU ld version 2.13.90.0.18 20030206

Q: How do I know whether they are FSF's or HJL's?

Thanks.
-- 
Ricardo Barberis
Usuario Linux Nº 250625:           http://counter.li.org
Usuario LFS Nº 5121:               http://www.linuxfromscratch.org
LFS en castellano:                 http://www.lfs-es.org
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.