Bugtraq mailing list archives

Re: local root on linux 2.2.15


From: cadence () APOLLO ACI COM PL (Tomasz Grabowski)
Date: Thu, 8 Jun 2000 21:54:51 +0200


I did not discover this bug, I only extrapolated from the small info I had:
'it has to do with capsuid' 'sendmail is vulnerable, crond is not'. Some
reading of the kernel source then suggested the above to me, which has been
confirmed by a more knowledgeable source.

Crontab IS vulnerable, but it will only give you egid=0 (at least at
RedHat 5.1 with 2.2.12 kernel).


Current thread: