Showing posts with label local vulnerability. Show all posts
Showing posts with label local vulnerability. Show all posts

Monday, February 18, 2013

In the Linux kernel found local vulnerability


There is evidence about the discovery in the Linux kernel vulnerability (CVE-2013-0871) in the subsystem PTRACE, which can be exploited by a local attacker to execute code in the kernel.

To demonstrate the potential for exploitation of the vulnerability exploited by a prototype for the sheer work that requires small changes to the core, simplifying manifestation of the race when called with a parameter ptrace PTRACE_SETREGS.

How realistic is operated under normal conditions the problem and the circumstances that may contribute to the fact it is not clear yet is considered to be attacked only in theory. However, it is possible that the problem is one of the most dangerous vulnerabilities in the kernel in the past few years.