Vulnerability Development mailing list archives

Re: Local root through vulnerability in ping on linux.


From: Gerrie <gerrie () HIT2000 ORG>
Date: Sun, 20 Aug 2000 11:20:44 +0200

----- Original Message -----
From: "Ralf-Philipp Weinmann"
On Sat, 19 Aug 2000, Gerrie wrote:

Again some blackhats have a zeroday exploits in their hands.

It's exploits a bug in the linux kernel by using ping, does someone have
more info?


Does that bug actually allow you to increase your privs or is it DoS
only ? What kernel versions are concerned ?

No it's a exploit to gain root -all evidence point that way-.

We haven't reconstructed the situation -yet- and don't have any trace of the
exploit.

The only fact there is that they had root, and it was a 2.2.16 kernel.


gtx,
Gerrie
btw: didn't ADM have a zeroday ?


Current thread: