|
Linux Kernel do_brk Function Boundary Condition Vulnerability
A reliable exploit to provide for privilege escalation has been developed by Paul Starzetz <ihaquer@isec.pl> and Wojciech Purczynski <cliph@isec.pl>. This exploit is presented in the following document: http://isec.pl/papers/linux_kernel_do_brk.pdf Debian has stated that a program designed to exploit this issue was discovered and analyzed on a compromised system. This exploit is not publicly available, however can be assumed that this program is being used to actively exploit systems in the wild. A proof of concept exploit designed to crash a system has been made available by Christophe Devine <DEVINE@iie.cnam.fr>. A second proof of concept making use of the sys_brk kernel call has been developed and supplied by Julien TINNES <julien@cr0.org>. CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild. |
|
|
Privacy Statement |