SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#628849

ptrace contains vulnerability allowing for local root compromise

Overview

A vulnerability in the Linux 2.2 and 2.4 distributions of ptrace() may permit a local attacker to gain elevated privileges.

I. Description

The Linux 2.2 and 2.4 kernels contained a flaw in ptrace(). This vulnerability may permit a local user to have the kernel spawn a child process. From the man page:

    The ptrace system call provides a means by which a parent process may observe and control the execution of another process, and examine and change its core image and registers. It is primarily used to implement breakpoint debugging and system call tracing.



If the kernel is built with modules and kernel module loader enabled and /proc/sys/kernel/modprobe contains the path to a valid executable and ptrace() calls are not blocked, then a local user may be able to exploit this vulnerability to gain root privileges to the system.

The CERT/CC has seen active exploitation of this vulnerability.

II. Impact

A local user can exploit this vulnerability to gain elevated privileges, typically root.

III. Solution

This vulnerability has been resolved in Linux 2.2.25 and 2.4.21. Various vendors have also released advisories and updates. Please see the your vendor's advisory for more details.

Systems Affected

VendorStatusDate Updated
ConectivaVulnerable16-Apr-2004
DebianVulnerable16-Apr-2004
GentooVulnerable16-Apr-2004
Guardian Digital Inc. Vulnerable16-Apr-2004
Linux Kernel ArchivesVulnerable16-Apr-2004
MandrakeSoftVulnerable16-Apr-2004
Red Hat Inc.Vulnerable16-Apr-2004
SCOVulnerable16-Apr-2004
SlackwareVulnerable16-Apr-2004
SuSE Inc.Vulnerable16-Apr-2004
TrustixVulnerable16-Apr-2004

References


http://www.securityfocus.com/bid/7112

Credit

Thanks to Andrzej Szombierski for reporting this vulnerability.

This document was written by Jason A Rafail and is based on information provided by Andrzej Szombierski.

Other Information

Date Public03/17/2003
Date First Published04/16/2004 03:08:58 PM
Date Last Updated04/30/2004
CERT Advisory 
CVE-ID(s)CAN-2003-0127
NVD-ID(s)CAN-2003-0127
US-CERT Technical Alerts 
Metric14.25
Document Revision9

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader