Linux Ptrace/Setuid Exec漏洞

漏洞信息详情

Linux Ptrace/Setuid Exec漏洞

漏洞简介

Linux 2.2.x至2.2.19,和2.4.x至2.4.9版本中ptrace存在漏洞。本地用户通过在setuid或者setgid程序中运行ptrace提升根特权,setgid程序调用无特权的程序,比如newgrp。

漏洞公告

An unofficial kernel patch has been made available by Nergal.
Upgrades are also available from a number of vendors.
RedHat kernel-source-2.4.7-10.i386.rpm

RedHat kernel-headers-2.4.7-10.i386.rpm

RedHat kernel-2.4.7-10.i386.rpm

RedHat kernel-2.4.7-10.i686.rpm

RedHat kernel-BOOT-2.4.7-10.i386.rpm

RedHat kernel-doc-2.4.7-10.i386.rpm

Linux kernel 2.2.10

Linux kernel 2.2.14

参考网址

来源: ENGARDE
名称: ESA-20011019-02
链接:http://www.linuxsecurity.com/advisories/other_advisory-1650.html

来源: XF
名称: linux-ptrace-race-condition(7311)
链接:http://www.iss.net/security_center/static/7311.php

来源: REDHAT
名称: RHSA-2001:130
链接:http://www.redhat.com/support/errata/RHSA-2001-130.html

来源: REDHAT
名称: RHSA-2001:129
链接:http://www.redhat.com/support/errata/RHSA-2001-129.html

来源: SUSE
名称: SuSE-SA:2001:036
链接:http://www.novell.com/linux/security/advisories/2001_036_kernel_txt.html

来源: MANDRAKE
名称: MDKSA-2001:082
链接:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3

来源: MANDRAKE
名称: MDKSA-2001:079
链接:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-079.php3

来源: HP
名称: HPSBTL0112-003
链接:http://online.securityfocus.com/advisories/3713

来源: IMMUNIX
名称: IMNX-2001-70-035-01
链接:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01

来源: CALDERA
名称: CSSA-2001-036.0
链接:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt

来源: BID
名称: 3447
链接:http://www.securityfocus.com/bid/3447

来源: BUGTRAQ
名称: 20011019 TSLSA-2001-0028
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100350685431610&w=2

来源: BUGTRAQ
名称: 20011018 Flaws in recent Linux kernels
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100343090106914&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享