Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
BID:38702
Info
Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 38702 |
| Class: | Design Error |
| CVE: |
CVE-2010-0729 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 12 2010 12:00AM |
| Updated: | Apr 01 2013 10:27AM |
| Credit: | Eugene Teo |
| Vulnerable: |
RedHat Enterprise Linux WS 4 RedHat Enterprise Linux ES 4.8.z RedHat Enterprise Linux ES 4.7.z RedHat Enterprise Linux ES 4.6.z RedHat Enterprise Linux ES 4.5.z RedHat Enterprise Linux ES 4 RedHat Enterprise Linux Desktop version 4 Red Hat Enterprise Linux AS 4.8.z Red Hat Enterprise Linux AS 4.7.z Red Hat Enterprise Linux AS 4.6.z Red Hat Enterprise Linux AS 4.5.z Red Hat Enterprise Linux AS 4 Avaya Voice Portal 5.1 SP1 Avaya Voice Portal 5.1 Avaya Voice Portal 4.1 SP2 Avaya Voice Portal 4.1 SP1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Proactive Contact 4.1.2 Avaya Proactive Contact 4.1.1 Avaya Proactive Contact 3.0.3 Avaya Proactive Contact 3.0.2 Avaya Proactive Contact 4.1 Avaya Proactive Contact 4.0 Avaya Proactive Contact 3.0 Avaya Messaging Storage Server 5.2 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 |
| Not Vulnerable: |
Avaya Proactive Contact 4.2.1 |
Discussion
Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
Red Hat Enterprise Linux 4 is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with elevated privileges, possibly resulting in a complete compromise of the affected computer.
Red Hat Enterprise Linux 4 on ia64 platforms is vulnerable.
Red Hat Enterprise Linux 4 is prone to a local privilege-escalation vulnerability.
A local attacker can exploit this issue to execute arbitrary code with elevated privileges, possibly resulting in a complete compromise of the affected computer.
Red Hat Enterprise Linux 4 on ia64 platforms is vulnerable.
Exploit / POC
Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
References:
References:
- Bug 572007 �?? CVE-2010-0729 kernel: ia64: ptrace: peek_or_poke requests miss ptra (Eugene Teo)
- CVE-2010-0729 kernel: ia64: ptrace: peek_or_poke requests miss ptrace_check_atta (Eugene Teo)
- Red Hat Homepage (Red Hat)
- ASA-2010-146 kernel security, bug fix, and enhancement update (RHSA-2010-0394 RH (Avaya)