Kernel 2.4 ioperm

2003-05-22 Thread xbud
FYI, http://marc.theaimsgroup.com/?|=linux-kernel&m=105271679705571&w=2 -- -- Orlando Padilla http://www.g0thead.com/xbud.asc "I only drink to make other people interesting" --

Re: Kernel 2.4 ioperm

2003-05-22 Thread Simon Huggins
On Thu, May 22, 2003 at 01:50:51PM -0600, xbud wrote: > FYI, http://marc.theaimsgroup.com/?|=linux-kernel&m=105271679705571&w=2 You say 2.4 in the subject and it says 2.5 in that report. Is 2.4 vulnerable too? In a reduced test on 2.4 ioperm succeeds as a user but I'm reluctant to actually run t

Re: Kernel 2.4 ioperm

2003-05-22 Thread xbud
On Thursday 22 May 2003 15:16, Simon Huggins wrote: > On Thu, May 22, 2003 at 01:50:51PM -0600, xbud wrote: > > FYI, http://marc.theaimsgroup.com/?|=linux-kernel&m=105271679705571&w=2 > > You say 2.4 in the subject and it says 2.5 in that report. > > Is 2.4 vulnerable too? > Yes. > In a reduced te

Re: Kernel 2.4 ioperm

2003-05-22 Thread Martin Helas
On Don Mai 22, 2003 at 10:1621 +0100, Simon Huggins <[EMAIL PROTECTED]> wrote: > On Thu, May 22, 2003 at 01:50:51PM -0600, xbud wrote: > > FYI, http://marc.theaimsgroup.com/?|=linux-kernel&m=105271679705571&w=2 > > You say 2.4 in the subject and it says 2.5 in that report. > > Is 2.4 vulnerable t

Re: Kernel 2.4 ioperm

2003-05-23 Thread Steffen Schulz
On 030523 at 13:20, Martin Helas wrote: > On Don Mai 22, 2003 at 10:1621 +0100, Simon Huggins <[EMAIL PROTECTED]> wrote: > > On Thu, May 22, 2003 at 01:50:51PM -0600, xbud wrote: > > > FYI, http://marc.theaimsgroup.com/?|=linux-kernel&m=105271679705571&w=2 > > > > You say 2.4 in the subject and it

Re: Kernel 2.4 ioperm

2003-05-23 Thread Thomas Krennwallner
Hi! On Fri May 23, 2003 at 04:16:22PM +0200, Steffen Schulz wrote: > Am I right that a local User is able to crash the system > by putting evil data into these mysterious I/O-Ports? > Is privilege escalation possible? > > Is this exploitable out of a chroot-jail(ssh,postfix)? AFAICS this bug is

Re: Kernel 2.4 ioperm

2003-05-23 Thread Adam ENDRODI
On Fri, May 23, 2003 at 04:16:22PM +0200, Steffen Schulz wrote: > > Am I right that a local User is able to crash the system > by putting evil data into these mysterious I/O-Ports? I'm not sure, but I don't *think* that the attacker is free to chose any target port. > Is privilege escalation pos