FS#21435 - [glibc 2.12.1-2] local privilege escalation

Attached to Project: Arch Linux
Opened by Sébastien Luttringer (seblu) - Saturday, 23 October 2010, 17:05 GMT
Last edited by Allan McRae (Allan) - Monday, 25 October 2010, 07:26 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To Allan McRae (Allan)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Description:

Current glibc upstream is vulnerable to easy local root exploit : CVE-2010-3847 CVE-2010-3856.

i've tested the following exploit : http://www.exploit-db.com/exploits/15304/ on my up-to-date arch system and it was succeful (after some modifications).

Politics of arch is to update only from upstream, but i'm wondering if security issue (like this one) you push some patch manually?

This task depends upon

Closed by  Allan McRae (Allan)
Monday, 25 October 2010, 07:26 GMT
Reason for closing:  Fixed
Additional comments about closing:  glibc-2.12.1-3
Comment by Allan McRae (Allan) - Saturday, 23 October 2010, 21:33 GMT
Can you give instructions on how to use the exploit in Arch? That would convince me to pull the patch...
Comment by jozef riha (jose1711) - Saturday, 23 October 2010, 21:38 GMT
the instructions are at web address given in the bugreport. but basically just run:

umask 0;LD_AUDIT="libpcprofile.so" PCPROFILE_OUTPUT="/etc/cron.d/exploit" ping; ls -l /etc/cron.d/exploit

and you'll realize there's something wrong..
Comment by Allan McRae (Allan) - Saturday, 23 October 2010, 22:18 GMT
Sorry, I thought this was the recent $ORIGIN issues which does not work on Arch... It seems that this one does.

I will look into the patch. Urlich seems to want to give it some thought before accepting into glibc which tells me that this change is not one to be taken lightly...
Comment by Sébastien Luttringer (seblu) - Saturday, 23 October 2010, 23:00 GMT
do you know where Ulrich said that?
Comment by Allan McRae (Allan) - Sunday, 24 October 2010, 08:31 GMT

Loading...