Bugtraq mailing list archives

Re: COSEINC Linux Advisory #1: Linux Kernel Parent Process Death Signal Vulnerability


From: Wojciech Purczynski <cliph () isec pl>
Date: Wed, 15 Aug 2007 23:37:53 +0200 (CEST)


Could you please explain it to me where do you see privilege escalation
here?

Sending a signal to privileged process is a privilege itself. Under some
circumstances this may lead to other consequences. For example I was able
to code local root exploit using some very common suid binary, although
its usage is somewhat limited.


Current thread: