Linux Kernel Privileged Process Hijacking Vulnerability
BID:7112
Info
Linux Kernel Privileged Process Hijacking Vulnerability
| Bugtraq ID: | 7112 |
| Class: | Design Error |
| CVE: |
CVE-2003-0127 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 17 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | The discovery of this vulnerability has been credited to Andrzej Szombierski. |
| Vulnerable: |
Redhat Linux Advanced Work Station 2.1 Redhat Enterprise Linux AS 2.1 IA64 Linux kernel 2.4.21 pre1 Linux kernel 2.4.20 Linux kernel 2.4.19 Linux kernel 2.4.18 Linux kernel 2.4.17 Linux kernel 2.4.16 Linux kernel 2.4.15 Linux kernel 2.4.14 Linux kernel 2.4.13 Linux kernel 2.4.12 Linux kernel 2.4.11 Linux kernel 2.4.10 Linux kernel 2.4.9 Linux kernel 2.4.8 Linux kernel 2.4.7 Linux kernel 2.4.6 Linux kernel 2.4.5 Linux kernel 2.4.4 Linux kernel 2.4.3 Linux kernel 2.4.2 Linux kernel 2.4.1 Linux kernel 2.4 Linux kernel 2.2.24 Linux kernel 2.2.23 Linux kernel 2.2.22 Linux kernel 2.2.21 Linux kernel 2.2.20 Linux kernel 2.2.19 Linux kernel 2.2.18 Linux kernel 2.2.17 Linux kernel 2.2.16 Linux kernel 2.2.15 Linux kernel 2.2.14 Linux kernel 2.2.13 Linux kernel 2.2.12 Linux kernel 2.2.11 Linux kernel 2.2.10 Linux kernel 2.2.9 Linux kernel 2.2.8 Linux kernel 2.2.7 Linux kernel 2.2.6 Linux kernel 2.2.5 Linux kernel 2.2.4 Linux kernel 2.2.3 Linux kernel 2.2.2 Linux kernel 2.2.1 Linux kernel 2.2 EnGarde Secure Professional 1.5 EnGarde Secure Community 2.0 |
| Not Vulnerable: |
Linux kernel 2.5.32 Linux kernel 2.5.31 Linux kernel 2.5.30 Linux kernel 2.5.29 Linux kernel 2.5.28 Linux kernel 2.5.27 Linux kernel 2.5.26 Linux kernel 2.5.25 Linux kernel 2.5.24 Linux kernel 2.5.23 Linux kernel 2.5.22 Linux kernel 2.5.21 Linux kernel 2.5.20 Linux kernel 2.5.19 Linux kernel 2.5.18 Linux kernel 2.5.17 Linux kernel 2.5.16 Linux kernel 2.5.15 Linux kernel 2.5.14 Linux kernel 2.5.13 Linux kernel 2.5.12 Linux kernel 2.5.11 Linux kernel 2.5.10 Linux kernel 2.5.9 Linux kernel 2.5.8 Linux kernel 2.5.7 Linux kernel 2.5.6 Linux kernel 2.5.5 Linux kernel 2.5.4 Linux kernel 2.5.3 Linux kernel 2.5.2 Linux kernel 2.5.1 Linux kernel 2.5 .0 Linux kernel 2.4.21 pre1 Linux kernel 2.4.21 Linux kernel 2.2.25 CRUX CRUX Linux 1.1 |
Discussion
Linux Kernel Privileged Process Hijacking Vulnerability
A vulnerability has been discovered in the Linux kernel which can be exploited using the ptrace() system call. By attaching to an incorrectly configured root process, during a specific time window, it may be possible for an attacker to gain superuser privileges.
The problem occurs due to the kernel failing to restrict trace permissions on specific root spawned processes.
This vulnerability affects both the 2.2 and 2.4 Linux kernel trees.
A vulnerability has been discovered in the Linux kernel which can be exploited using the ptrace() system call. By attaching to an incorrectly configured root process, during a specific time window, it may be possible for an attacker to gain superuser privileges.
The problem occurs due to the kernel failing to restrict trace permissions on specific root spawned processes.
This vulnerability affects both the 2.2 and 2.4 Linux kernel trees.
Exploit / POC
Linux Kernel Privileged Process Hijacking Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploits have been released by Wojciech Purczynski <[email protected]>, Andrzej Szombierski <[email protected]>, anonymous KuRaK, and snooq.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploits have been released by Wojciech Purczynski <[email protected]>, Andrzej Szombierski <[email protected]>, anonymous KuRaK, and snooq.
References
Linux Kernel Privileged Process Hijacking Vulnerability
References:
References:
- CRUX Homepage (CRUX)
- Homepage (grsecurity)
- Linux kmod-ptrace race condition exploit (CORE Security)
- Ptrace hole / Linux 2.2.25 (Linux-Kernel Mailing LIst)
- RHSA-2003-098 (Red Hat)
- RHSA-2003-103 (Red Hat)
- Sun Alert ID: 52081 (Sun)
- WOLK Homepage (WOLK)
- [Sorcerer-spells] LINUX-SORCERER2003-03-20 (Michael Walton
) - linux kmod/ptrace bug - details (Andrzej Szombierski
) - Red Hat IA64 products still missing fixes for the ptrace vs kmod vulnerability (Christoph Hellwig
)