Full Disclosure mailing list archives
Re: [DSA 444-1] New Linux 2.4.17 packages fix local root exploit (ia64)
From: Wojciech Purczynski <cliph () isec pl>
Date: Fri, 20 Feb 2004 12:49:43 +0100 (CET)
-------------------------------------------------------------------------- Debian Security Advisory DSA 444-1 security () debian org http://www.debian.org/security/ Martin Schulze February 20th, 2004 http://www.debian.org/security/faq -------------------------------------------------------------------------- Package : kernel-image-2.4.17-ia64 Vulnerability : missing function return value check Problem-Type : local Debian-specific: no CVE ID : CAN-2004-0077 Paul Starzetz and Wojciech Purczynski of isec.pl discovered a critical security vulnerability in the memory management code of Linux inside the mremap(2) system call. Due to missing function return value check of internal functions a local attacker can gain root privileges.
This time I haven't played my role in this spectacle. Full credits go to Paul. Cheers, wp -- Wojciech Purczynski iSEC Security Research http://isec.pl/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- [SECURITY] [DSA 444-1] New Linux 2.4.17 packages fix local root exploit (ia64) debian-security-announce (Feb 20)
- Re: [DSA 444-1] New Linux 2.4.17 packages fix local root exploit (ia64) Wojciech Purczynski (Feb 20)