kernel ELF loader core dump vulnerability

Ken Moffat <[email protected]> Thu, 12 May 2005 12:42:39 +0100 (BST)
Newsgroups gmane.linux.lfs.security
Message-ID <Pine.LNX.4.58.0505121235020.22094@ppg_penguin.kenmoffat.uklinux.net>
Paraphrasing lwn.net, by using a specially manipulated ELF binary, a
local attacker can root the system via the core dump code.

Applies to all kernels from 2.2 through 2.6.12-rc4.  Fix (for
binfmt_elf.c) is in 2.6.11.9 and appears to also apply to 2.6.12-rc.

So far, no word on fix for 2.4.

Ken
--=20
 das eine Mal als Trag=F6die, das andere Mal als Farce

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page