SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


Try our Premium Alert Service
 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service





Category:   OS (Linux)  >   Linux Kernel Vendors:   kernel.org
Linux Kernel binfmt_elf Loader Lets Local Users Obtain Root Access
SecurityTracker Alert ID:  1012165
SecurityTracker URL:  http://securitytracker.com/id/1012165
CVE Reference:   CVE-2004-1070, CVE-2004-1071, CVE-2004-1072, CVE-2004-1073, CVE-2004-1074   (Links to External Site)
Updated:  Dec 1 2004
Original Entry Date:  Nov 10 2004
Impact:   Execution of arbitrary code via local system, Root access via local system

Version(s): 2.4 through 2.4.27, 2.6 through 2.6.8
Description:   Some vulnerabilities were reported in the Linux kernel in the binfmt_elf loader. A local user can obtain root privileges on the target system.

Paul Starzetz reported several flaws in the ELF loader in the processing of set user id (setuid) binaries. These flaws include incorrect return value validation in the load_elf_binary() function, some faulty error handling, and an unterminated string bug in 'binfmt_elf.c' and also a file-type validation bug in 'exec.c' that allows non-readable ELF binaries to be read.

A local user can exploit these flaws to cause a setuid binary to execute arbitrary code.

The original advisory, including some demonstration exploit code, is available at:

http://isec.pl/vulnerabilities/isec-0017-binfmt_elf.txt

Impact:   A local user can execute arbitrary code with setuid privileges to obtain root access on the target system.
Solution:   No solution was available at the time of this entry.
Vendor URL:  www.kernel.org/ (Links to External Site)
Cause:   Access control error, Boundary error, Exception handling error, Input validation error

Message History:   This archive entry has one or more follow-up message(s) listed below.
Dec 2 2004 (SuSE Issues Fix) Linux Kernel binfmt_elf Loader Lets Local Users Obtain Root Access
SUSE has released a fix.
Dec 14 2004 (Turbolinux Issues Fix) Linux Kernel binfmt_elf Loader Lets Local Users Obtain Root Access
Turbolinux has issued a fix.
May 18 2005 (Red Hat Issues Fix) Linux Kernel binfmt_elf Loader Lets Local Users Obtain Root Access
Red Hat has issued a fix.
May 19 2005 (Red Hat Issues Fix) Linux Kernel binfmt_elf Loader Lets Local Users Obtain Root Access
Red Hat has released a fix for ia32el.



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2018, SecurityGlobal.net LLC