Re: [Full-disclosure] CAN-2004-1073 not fixed

From: Martin Pitt (martin.pitt_at_canonical.com)
Date: 03/30/05

  • Next message: jamie fisher: "[Full-disclosure] BO in http://rad.msn.com/ADSAdClient31.dll"
    Date: Wed, 30 Mar 2005 11:21:35 +0200
    To: full-disclosure@lists.grok.org.uk
    
    
    
    

    Hi!

    Santosh Eraniose [2005-03-29 16:39 +0530]:
    > On executing the PoC on 2.4.29 and 2.6.11 kernel we initially get
    > no core dump. The following code introduced to fix another bug, caused
    > the loading of the interpreter to fail.
    > [...]
    > With this change, on executing the PoC on 2.4.29 and 2.6.11,
    > the core dump contains the suid executable.
    > We used the strings command to check if the strings in the suid
    > is present in the core.
    >
    > So we find that the vulnerability of reading non-readable
    > binaries exist in the latest kernel and the vendor provided patch
    > for CAN-2004-1073 does not fix this vulnerability.

    Confirmed.

    I tried this on a security-patched 2.6.8.1 (Ubuntu 4.10) and 2.6.10
    (Ubuntu 5.04) kernel. With the modified PoC I was able to read a
    setuid binary with 4701 permissions on all kernels.

    Martin

    -- 
    Martin Pitt               http://www.piware.de
    Ubuntu Developer    http://www.ubuntulinux.org
    Debian Developer         http://www.debian.org
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: jamie fisher: "[Full-disclosure] BO in http://rad.msn.com/ADSAdClient31.dll"

    Relevant Pages

    • Re: /proc/net/stats process hang/crash
      ... Anytime after that the process hangs ... a locate -u will first core dump then the second time hang. ... > Both machines are pretty much default new installations. ... Looks like a kernel bug. ...
      (Fedora)
    • [PATCH] MIPS: o32 application running on 64bit kernel core dump
      ... If an o32 application crashes and generates a core dump on ... and will use the default register set which would ... * When this file is selected, we are definitely running a 64bit kernel. ...
      (Linux-Kernel)
    • panic, then trashed IDE drive - from kernel dump?
      ... The last known good state of my system was a world and kernel from ... Aug 24 at approx 12:00 EDT. ... It completed a core dump, ... the disk and restore from backup. ...
      (freebsd-current)
    • Re: FreeBSD 4.9 RC1 (more bad news)
      ... > (only the system reset button can unwedge it) during device configuration. ... the kernel was wedging by inserting printfs in the kernel source ... Since the kernel wedges so hard, there it no way to interrupt ... it and force a core dump or take a stack trace. ...
      (freebsd-stable)
    • Re: 5.4-RC2: Unexpected reboots
      ... If its a software bug thats causing the machine to crash, ... dumpon so that you have at least a core dump that will tell you where ... dumpon -v /dev/ad0s1b ... Build a kernel with debug symbols (dont worry, ...
      (freebsd-questions)