Systrace 64-Bit Aware Linux Kernel Privilege Escalation Vulnerability
BID:33417
Info
Systrace 64-Bit Aware Linux Kernel Privilege Escalation Vulnerability
| Bugtraq ID: | 33417 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 23 2009 12:00AM |
| Updated: | Jan 27 2009 03:49PM |
| Credit: | Chris Evans |
| Vulnerable: |
Niels Provos Systrace 1.5 Niels Provos Systrace 1.4 Niels Provos Systrace 1.3 Niels Provos Systrace 1.2 Niels Provos Systrace 1.1 Niels Provos Systrace 1.6e |
| Not Vulnerable: |
Niels Provos Systrace 1.6f |
Discussion
Systrace 64-Bit Aware Linux Kernel Privilege Escalation Vulnerability
Systrace is prone to a local privilege-escalation vulnerability.
A local attacker may be able to exploit this issue to bypass access control restrictions and make unintended system calls, which may result in an elevation of privileges.
Versions prior to Systrace 1.6f are vulnerable.
Systrace is prone to a local privilege-escalation vulnerability.
A local attacker may be able to exploit this issue to bypass access control restrictions and make unintended system calls, which may result in an elevation of privileges.
Versions prior to Systrace 1.6f are vulnerable.
Exploit / POC
Systrace 64-Bit Aware Linux Kernel Privilege Escalation Vulnerability
The following example exploit is available:
The following example exploit is available:
Solution / Fix
Systrace 64-Bit Aware Linux Kernel Privilege Escalation Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Systrace 64-Bit Aware Linux Kernel Privilege Escalation Vulnerability
References:
References:
- CESA-2009-001 - rev 1: Linux syscall interception technologies partial bypass (Chris Evans)
- Systrace 1.6f with 64-bit Linux ptrace support (Niels Provos)
- Systrace Homepage (Niels Provos)
- Problems with syscall filtering technologies on Linux (Chris Evans
)