[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: COSEINC Linux Advisory #1: Linux Kernel Parent Process Death Signal Vulnerability
- To: Dan Yefimov <dan@xxxxxxxxxxxxxxxxxxxxx>
- Subject: Re: COSEINC Linux Advisory #1: Linux Kernel Parent Process Death Signal Vulnerability
- From: Wojciech Purczynski <cliph@xxxxxxx>
- Date: Wed, 15 Aug 2007 23:37:53 +0200 (CEST)
> Could you please explain it to me where do you see privilege escalation
> here?
Sending a signal to privileged process is a privilege itself. Under some
circumstances this may lead to other consequences. For example I was able
to code local root exploit using some very common suid binary, although
its usage is somewhat limited.