ATTN FreeBSD 7/8 users! Local root exploit patch

Discussion in 'all things UNIX' started by Kevin McAleavey, Dec 1, 2009.

Thread Status:
Not open for further replies.
  1. Kevin McAleavey

    Kevin McAleavey Security Expert

    Joined:
    Dec 8, 2003
    Posts:
    376
    Location:
    Upstate New York
    FreeBSD Security Team official statement and PATCH

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Hi all,

    A short time ago a "local root" exploit was posted to the full-disclosure
    mailing list; as the name suggests, this allows a local user to execute
    arbitrary code as root.

    Normally it is the policy of the FreeBSD Security Team to not publicly
    discuss security issues until an advisory is ready, but in this case
    since exploit code is already widely available I want to make a patch
    available ASAP. Due to the short timeline, it is possible that this
    patch will not be the final version which is provided when an advisory
    is sent out; it is even possible (although highly doubtful) that this
    patch does not fully fix the issue or introduces new issues -- in short,
    use at your own risk (even more than usual).

    The patch is at
    http://people.freebsd.org/~cperciva/rtld.patch
    and has SHA256 hash
    ffcba0c20335dd83e9ac0d0e920faf5b4aedf366ee5a41f548b95027e3b770c1

    I expect a full security advisory concerning this issue will go out on
    Wednesday December 2nd.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.10 (FreeBSD)

    iEYEARECAAYFAksUbjcACgkQFdaIBMps37LP9ACgljaYCfgVuhD2gd9Natpq4H/9
    i48An1mgl+Mih+AWN7J9KZ1rsiEU31IZ
    =MPXj
    -----END PGP SIGNATURE-----

    --
    Colin Percival
    Security Officer, FreeBSD | freebsd.org | The power to serve
    Founder / author, Tarsnap | tarsnap.com | Online backups for the truly paranoid

    ---

    Yes, this one's serious ... rtld.c needs to be patched and recompiled. There is a POC posted with which you can check your own system for the presence of this vulnerability here:

    http://seclists.org/fulldisclosure/2009/Nov/371

    Patching immediately is highly recommended ... NOW!
     
  2. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    I'd just read the notification in my mail and was also going to post so thanks Kevin.
     
Loading...
Thread Status:
Not open for further replies.