Grsecurity内核PaX本地权限提升漏洞

漏洞信息详情

Grsecurity内核PaX本地权限提升漏洞

漏洞简介

Grsecurity Linux是一款开放源代码操作系统。

Grsecurity的expand_stack()函数实现上存在漏洞,本地攻击者可能利用此漏洞以root用户权限执行任意指令。

漏洞公告

目前厂商还没有提供补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:

http://www.grsecurity.net

参考网址

来源: BID

名称: 22014

链接:http://www.securityfocus.com/bid/22014

来源: BUGTRAQ

名称: 20070309 Re: Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/462302/100/100/threaded

来源: BUGTRAQ

名称: 20070120 Digital Armaments Security Advisory 20.01.2007: Grsecurity Kernel PaX Vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/457509/100/0/threaded

来源: BUGTRAQ

名称: 20070112 Lies? [Was: Re: Digital Armaments Security Pre-Advisory11.01.2007: Grsecurity Kernel PaX – Local root vulnerability]

链接:http://www.securityfocus.com/archive/1/archive/1/456722/100/0/threaded

来源: BUGTRAQ

名称: 20070111 Digital Armaments Security Pre-Advisory 11.01.2007: Grsecurity Kernel PaX – Local root vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/456626/100/0/threaded

来源: VUPEN

名称: ADV-2007-0155

链接:http://www.frsirt.com/english/advisories/2007/0155

来源: MISC

链接:http://www.digitalarmaments.com/pre2007-00018659.html

来源: MISC

链接:http://www.digitalarmaments.com/news_news.shtml

来源: SECTRACK

名称: 1017509

链接:http://securitytracker.com/id?1017509

来源: SECUNIA

名称: 23713

链接:http://secunia.com/advisories/23713

来源: OSVDB

名称: 32727

链接:http://osvdb.org/32727

来源: MISC

链接:http://grsecurity.net/news.php#digitalfud

来源: MISC

链接:http://forums.grsecurity.net/viewtopic.php?t=1646

来源:NSFOCUS
名称:9809
链接:http://www.nsfocus.net/vulndb/9809

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享