漏洞描述
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.securityfocus.comhttp://www.securityfocus.com/bid/51625↗www.redhat.comhttp://www.redhat.com/support/errata/RHSA-2012-0052.html↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2012/01/22/4↗ubuntu.comhttp://ubuntu.com/usn/usn-1336-1↗secunia.comhttp://secunia.com/advisories/47708↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2012/01/18/2↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2012/01/19/4↗www.kernel.orghttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.2↗www.redhat.comhttp://www.redhat.com/support/errata/RHSA-2012-0061.html↗bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=782642↗blog.zx2c4.comhttp://blog.zx2c4.com/749↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2012/01/18/1↗www.kb.cert.orghttp://www.kb.cert.org/vuls/id/470151↗git.kernel.orghttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commitdiff%3Bh=e268337dfe26dfc7efd422a804dbb27977a3cccc↗