|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Pavel Vasilyev 2:5020/1042.65 10 Nov 2005 00:00:46 To : Pavel Vasilyev Subject : Грабля -------------------------------------------------------------------------------- Ещё одна. TITLE: Linux Kernel Console Keyboard Mapping Shell Command Injection IMPACT: Privilege escalation WHERE: Local system REVISION: 2.0 originally posted 2005-10-17 OPERATING SYSTEM: Linux Kernel 2.6.x DESCRIPTION: Rudolf Polzer has reported a vulnerability in the Linux Kernel, which potentially can be exploited by malicious, local users to gain escalated privileges. The vulnerability is caused due to the way console keyboard mapping is handled. The keyboard map installed by a local user using "loadkeys" is applied to all virtual consoles and is not being reset after the user logs out. Successful exploitation allows malicious console users to inject arbitrary shell commands into certain key mappings, which are executed when the next logon console user uses the re-mapped key. The vulnerability has been reported in Kernel 2.6. Other versions may also be affected. SOLUTION: The vulnerability has been fixed in version 2.6.14-git12. Kernel.org: http://kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0b36 0adbdb54d 5+b98b78d57ba0916bc4b8871968 Memento morri Pavel! --- GoldED+ 1.1.5 (Linux 2.6.14 i686) * Origin: Windows 3.1/95/98/ME/XP/NT/2000/2003 Rulezzz !!! (2:5020/1042.65) Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/456843725601.html, оценка из 5, голосов 10
|