|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
A local overflow exists in the 'ld-linux.so' dynamic linkers in some Linux distributions. By forcing an error while calling a dynamically linked setuid program with a long program name (argv[0]), a local attacker can overflow a buffer and execute arbitrary code on the system gaining root privileges.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Upgrade to ld.so/ld-linux.so 1.9.5 or higher or OpenLinux ld.so package 1.7.14-5 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
Caldera OpenLinux
 |
1.1 |
|
ld-linux.so
 |
0.x |
1.0 |
1.1 |
1.2 |
1.3 |
1.4 |
1.5 |
1.6 |
1.7 |
1.8 |
1.9 |
1.91 |
1.92 |
1.93 |
1.94 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|