LWN.net Logo

kernel: several vulnerabilities

kernel: several vulnerabilities

Posted Aug 23, 2007 11:57 UTC (Thu) by nix (subscriber, #2304)
Parent article: kernel: several vulnerabilities

No: 2.4.35 and kernels before 2.6.22.3 allow local users to send such signals by causing a *non-privileged*, attacker-controlled parent process to die: before dying it forks, sets the parent process death signal and kicks off a setuid child.

Now when it dies it hits the setuid *child* with whatever signal it chose.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds