Re: COSEINC Linux Advisory #1: Linux Kernel Parent Process Death

看板Bugtraq作者時間18年前 (2007/08/16 05:19), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串9/24 (看更多)
> In my eyes this is definitely a security issue. But I cannot imagine a > way to exploit this issue at the moment. First you have to find a suid > binary which fork()'s. Next thing is that you need access to that > binary. And then? If both conditions are really met, what's next? The > possibilities are depending a little bit on the suid binary, am I right? > Please feel free to correct me if I am wrong. You do not need suid that forks, you do the fork then child execves victim suid which then setuids and your parent execves another suid that exits or dies and thus the parent process death signal gets delivered to victim suid. It's all in my advisory.
文章代碼(AID): #16mstO00 (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 9 之 24 篇):
文章代碼(AID): #16mstO00 (Bugtraq)