Bug#458251: prctl exploit works on kernel 2.6.18.5

2007-12-30 Thread dann frazier
tag 458251 + unreproducible tag 458251 + moreinfo thanks On Sat, Dec 29, 2007 at 10:58:59PM +0200, Lex wrote: > Package: linux-image > Version: 2.6.18.5 > Tags: security > > Hello. > I'm running debian etch server. kernel 2.6.18.5, libc6_2.3.6.ds1-13etch2 > updated by aptitude yesterday. The str

Bug#458251: prctl exploit works on kernel 2.6.18.5

2007-12-29 Thread Lex
Package: linux-image Version: 2.6.18.5 Tags: security Hello. I'm running debian etch server. kernel 2.6.18.5, libc6_2.3.6.ds1-13etch2 updated by aptitude yesterday. Today my server was attacked. Attacker logged in as non privileged user "test".(password was brutforced). He used prctl local roo