Re: Kernel exploit in brk() function.
Ricardo Barberis <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Dattatec.com |
| Message-ID | <[email protected]> |
Christophe Devine wrote: > Ricardo Barberis <[email protected]> wrote: > >> However, in our servers we have a RH 7.2 with 2.4.18-27.7, a RH 7.3 >> with 2.4.20-18.7 and another with 2.4.18-27.7.xsmp which are NOT, and >> we have a RH with a vanilla 2.4.22 compiled by one of our guys and >> also is NOT vulnerable (I can keep posting about our servers if you >> want). Now a question, does RH's gcc-2.96 have anything to do about >> this? > > Possibly, I think it must also depend on the version of binutils; I > haven't started investigating this problem yet. However you may still > be vulnerable even if the exploit doesn't seem to work. There's a poc > code you can use to be 100% sure at: > http://packetstormsecurity.nl/filedesc/brk_poc.asm.html > > Christophe Nice piece of code, unfortunately we manage remote servers and I don't think the boss will like that we might reboot them :-) About binutils, these are the results of ld -v on the servers I checked so far: GNU ld version 2.11.93.0.2 20020207 GNU ld version 2.11.90.0.8 (with BFD 2.11.90.0.8) GNU ld version 2.13.90.0.18 20030206 Q: How do I know whether they are FSF's or HJL's? Thanks. -- Ricardo Barberis Usuario Linux Nº 250625: http://counter.li.org Usuario LFS Nº 5121: http://www.linuxfromscratch.org LFS en castellano: http://www.lfs-es.org -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page