OSVDB ID: 78509

Title: Linux Kernel /proc//mem Access Restriction Weakness Local Privilege Escalation

Info

Disclosure

Jan 17, 2012

Discovery

Unknown

Dates

Exploit

Jan 23, 2012

Solution

Jan 17, 2012

Description

Linux Kernel contains a flaw that leads to unauthorized privileges being gained. The issue is due to the mem_write function not properly validating permissions when writing to /proc/<pid>/mem and may allow a local attacker to gain privileges by modifying process memory.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS, Third-Party Solution
Exploit: Exploit Public
Disclosure: Vendor Verified, Third-party Verified
OSVDB: Authentication Required

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Linus Torvalds and multiple Linux distributions have released a patch to address this vulnerability. Check the related advisories, changelogs, or solutions in the references section.

Products

Linux Kernel Organization, Inc.

Kernel

2.6.39

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/78509