NetBSD Local PTrace Privilege Escalation Vulnerability
BID:15290
Info
NetBSD Local PTrace Privilege Escalation Vulnerability
| Bugtraq ID: | 15290 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 02 2005 12:00AM |
| Updated: | Nov 02 2005 12:00AM |
| Credit: | Tavis Ormandy reported this issue to the vendor, and Christos Zoulas fixed the issue. |
| Vulnerable: |
NetBSD NetBSD 2.1 NetBSD NetBSD 2.0.3 NetBSD NetBSD 2.0.2 NetBSD NetBSD 2.0.1 NetBSD NetBSD 2.0 NetBSD NetBSD 1.6.2 NetBSD NetBSD 1.6.1 NetBSD NetBSD 1.6 |
| Not Vulnerable: | |
Discussion
NetBSD Local PTrace Privilege Escalation Vulnerability
NetBSD is susceptible to a local privilege escalation vulnerability in its 'ptrace' process tracing facility. This issue is due to a failure of the kernel to properly validate if an executable is running with elevated privileges prior to allowing the process to be traced.
This issue allows local attackers to ptrace privileged processes. Attackers may call arbitrary system calls, and alter the behavior of the traced process. This likely leads to a full system compromise.
NetBSD is susceptible to a local privilege escalation vulnerability in its 'ptrace' process tracing facility. This issue is due to a failure of the kernel to properly validate if an executable is running with elevated privileges prior to allowing the process to be traced.
This issue allows local attackers to ptrace privileged processes. Attackers may call arbitrary system calls, and alter the behavior of the traced process. This likely leads to a full system compromise.
Exploit / POC
NetBSD Local PTrace Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
NetBSD Local PTrace Privilege Escalation Vulnerability
Solution:
NetBSD has released an advisory, and has incorporated fixes into the NetBSD CVS repository. Please see the referenced advisory for further information.
Solution:
NetBSD has released an advisory, and has incorporated fixes into the NetBSD CVS repository. Please see the referenced advisory for further information.
References
NetBSD Local PTrace Privilege Escalation Vulnerability
References:
References:
- NetBSD Homepage (NetBSD)
- NetBSD Security Page (NetBSD)