[UNIX] Linux Kernel 2.6.x PRCTL Core Dump Handling



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Linux Kernel 2.6.x PRCTL Core Dump Handling
------------------------------------------------------------------------


SUMMARY

Improper handling of Core Dump allows attackers to gain local root
privileges in Linux, allowing attackers to execute arbitrary programs as
root.

DETAILS

Vulnerable Systems:
* Linux Kernel 2.6.17.4 and prior
* Linux Kernel 2.6.16.24 and prior

The prctl() function allows to set the value 2 for PR_SET_DUMPABLE by
unprivileged processes. In case of a segmentation fault the core dump will
then be owned by the user root.
This could lead to a denial of service (disk consumption) or allow a local
user to gain root privileges.
The suid_dumpable support and prctl(PR_SET_DUMPABLE, 2) have been added
with the 2.6.13 kernel and Red Hat Enterprise Linux 4 contains a back port
of it.

Vendor Status:
The vendor has issued a fix:
<http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.17.y.git;a=commit;h=0af184bb9f80edfbb94de46cb52e9592e5a547b0> http://www.kernel.org/git/?p=linux/kernel/git/stable/linux-2.6.17.y.git;a=commit;h=0af184bb9f80edfbb94de46cb52e9592e5a547b0

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2451>
CVE-2006-2451


ADDITIONAL INFORMATION

The information has been provided by Red Hat.
The original article can be found at:
<http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=195902>
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=195902



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [UNIX] Linux Kernel ALSA snd_mem_proc_read Information Disclosure Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Linux Kernel ALSA snd_mem_proc_read Information Disclosure Vulnerability ...
    (Securiteam)
  • [UNIX] Linux Kernel SCTP-AUTH API Information Disclosure Vulnerability and NULL Pointer Derefere
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Linux Kernel SCTP-AUTH API Information Disclosure Vulnerability and NULL ... SCTP_STATIC int sctp_getsockopt(struct sock *sk, int level, int optname, ...
    (Securiteam)
  • [UNIX] FUSE Information Disclosure
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Lack of range validation in FUSE allows attackers to reveal information ... * Linux kernel 2.2 ... static int fuse_copy_pages(struct fuse_copy_state *cs, unsigned nbytes, ...
    (Securiteam)
  • [EXPL] Linux Kernel do_mremap Improved Test
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Linux Kernel ... do_mremap Local Privilege Escalation Vulnerability, ... * GNU General Public License for more details. ...
    (Securiteam)
  • [UNIX] Linux Kernel cpuset tasks Information Disclosure Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Linux Kernel cpuset tasks Information Disclosure Vulnerability ... In order to exploit this vulnerability, an attacker would need access to ...
    (Securiteam)