CVE-2013-2929: Low severity Linux Linux kernel vulnerability
Published Nov 7, 2013
·
Updated
Last updated 24 July 2024
Other sources
The getdumpable() return value is not boolean. Most users of the function actually want to be testing for non-SUIDDUMPUSER(1) rather than SUIDDUMPDISABLE(0). The SUIDDUMPROOT(2) is also considered a protected state.
If the system had set the sysctl fs.suiddumpable=2, a user was able to ptrace attach to processes that he would otherwise be unable to because of the dumpable check.
The Linux kernel before 3.12.2 does not properly use the getdumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.
SecAlerts Pty Ltd. 132 Wickham Terrace Fortitude Valley, QLD 4006, Australia info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.