漏洞信息详情
Linux Ptrace/Setuid Exec漏洞
- CNNVD编号:CNNVD-200110-072
- 危害等级: 高危
- CVE编号:
CVE-2001-1384
- 漏洞类型:
设计错误
- 发布时间:
2001-10-18
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
linux - 漏洞来源:
Reported to Bugtra… -
漏洞简介
Linux 2.2.x至2.2.19,和2.4.x至2.4.9版本中ptrace存在漏洞。本地用户通过在setuid或者setgid程序中运行ptrace提升根特权,setgid程序调用无特权的程序,比如newgrp。
漏洞公告
An unofficial kernel patch has been made available by Nergal.
Upgrades are also available from a number of vendors.
RedHat kernel-source-2.4.7-10.i386.rpm
-
RedHat 7.2 i386 kernel-source-2.4.9-7.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/kernel-source-2.4.9-7.i386.rpm
RedHat kernel-headers-2.4.7-10.i386.rpm
-
RedHat 7.2 i386 kernel-headers-2.4.9-7.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/kernel-headers-2.4.9-7.i386.rp
m
RedHat kernel-2.4.7-10.i386.rpm
-
RedHat 7.2 i386 kernel-2.4.9-7.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/kernel-2.4.9-7.i386.rpm
RedHat kernel-2.4.7-10.i686.rpm
-
RedHat 7.2 i386 kernel-2.4.9-7.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/kernel-2.4.9-7.i386.rpm
RedHat kernel-BOOT-2.4.7-10.i386.rpm
-
RedHat 7.2 i386 kernel-BOOT-2.4.9-7.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/kernel-BOOT-2.4.9-7.i386.rpm
RedHat kernel-doc-2.4.7-10.i386.rpm
-
RedHat 7.2 i386 kernel-doc-2.4.9-7.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/kernel-doc-2.4.9-7.i386.rpm
Linux kernel 2.2.10
-
Caldera 2.3 alpha linux-source-alpha-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 arm linux-source-arm-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 common linux-source-common-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 i386 linux-source-i386-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 linux-kernel-binary-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 linux-kernel-doc-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 linux-kernel-include-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 m68k linux-source-m68k-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 mips linux-source-mips-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 pcmcia-cs-3.0.14-4.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 ppc linux-source-ppc-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 sparc linux-source-sparc-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3 sparc64 linux-source-sparc64-2.2.10-13.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS
Linux kernel 2.2.14
-
Caldera 2.3.1 alpha linux-source-alpha-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 arm linux-source-arm-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 i386 linux-source-i386-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 linux-kernel-binary-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/2.3/current/RPMS -
Caldera 2.3.1 linux-kernel-doc-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 linux-kernel-include-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 m68k linux-source-m68k-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 mips linux-source-mips-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 pcmcia-cs-3.1.4-4.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 ppc linux-source-ppc-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 sparc linux-source-sparc-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.3.1 sparc64 linux-source-sparc64-2.2.14-12S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eServer/2.3/current/RPMS -
Caldera 2.4 arm linux-source-arm-2.2.14-8.i386.rpm
ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS -
Caldera 2.4 alpha linux-source-alpha-2.2.14-8.i386.rpm
ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS -
Caldera 2.4 common linux-source-common-2.4.2-13S.i386.rpm
ftp://ftp.caldera.com/pub/updates/eDesktop/2.4/current/RPMS -
Caldera 2.4 hwprobe-20000214-5.i386.rpm
ftp://ftp.caldera.com/p
参考网址
来源: ENGARDE
名称: ESA-20011019-02
链接:http://www.linuxsecurity.com/advisories/other_advisory-1650.html
来源: XF
名称: linux-ptrace-race-condition(7311)
链接:http://www.iss.net/security_center/static/7311.php
来源: REDHAT
名称: RHSA-2001:130
链接:http://www.redhat.com/support/errata/RHSA-2001-130.html
来源: REDHAT
名称: RHSA-2001:129
链接:http://www.redhat.com/support/errata/RHSA-2001-129.html
来源: SUSE
名称: SuSE-SA:2001:036
链接:http://www.novell.com/linux/security/advisories/2001_036_kernel_txt.html
来源: MANDRAKE
名称: MDKSA-2001:082
链接:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3
来源: MANDRAKE
名称: MDKSA-2001:079
链接:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-079.php3
来源: HP
名称: HPSBTL0112-003
链接:http://online.securityfocus.com/advisories/3713
来源: IMMUNIX
名称: IMNX-2001-70-035-01
链接:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01
来源: CALDERA
名称: CSSA-2001-036.0
链接:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt
来源: BID
名称: 3447
链接:http://www.securityfocus.com/bid/3447
来源: BUGTRAQ
名称: 20011019 TSLSA-2001-0028
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100350685431610&w=2
来源: BUGTRAQ
名称: 20011018 Flaws in recent Linux kernels
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=100343090106914&w=2