Debian DSA-276-1 : linux-kernel-s390 - local privilege escalation

high Nessus Plugin ID 15113

Synopsis

The remote Debian host is missing a security-related update.

Description

The kernel module loader in Linux 2.2 and Linux 2.4 kernels has a flaw in ptrace. This hole allows local users to obtain root privileges by using ptrace to attach to a child process that is spawned by the kernel. Remote exploitation of this hole is not possible.

This advisory only covers kernel packages for the S/390 architecture.
Other architectures will be covered by separate advisories.

Solution

Upgrade the kernel-images packages immediately.

For the stable distribution (woody) this problem has been fixed in the following versions :

- kernel-patch-2.4.17-s390: version 0.0.20020816-0.woody.1.1
- kernel-image-2.4.17-s390: version 2.4.17-2.woody.2.2

The old stable distribution (potato) is not affected by this problem for this architecture since s390 was first released with Debian GNU/Linux 3.0 (woody).

See Also

http://www.debian.org/security/2003/dsa-276

Plugin Details

Severity: High

ID: 15113

File Name: debian_DSA-276.nasl

Version: 1.20

Type: local

Agent: unix

Published: 9/29/2004

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:kernel-image-2.4.17-s390, p-cpe:/a:debian:debian_linux:kernel-patch-2.4.17-s390, cpe:/o:debian:debian_linux:3.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/3/2003

Reference Information

CVE: CVE-2003-0127

BID: 7112

DSA: 276