Re: ptrace secfix does NOT work... :(

Adam Majer (adamm@galacticasoftware.com)
Sat, 10 May 2003 16:25:48 -0500


This is a MIME-formatted message. If you see this text it means that your
E-mail software does not support MIME-formatted messages.

--=_courier-945-1052602265-0001-2
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, May 10, 2003 at 05:11:54PM -0400, Daniel Jacobowitz wrote:
> On Sat, May 10, 2003 at 03:52:49PM -0500, Adam Majer wrote:
> > On Fri, May 09, 2003 at 12:05:52AM +0200, Bernhard Kaindl wrote:
> > > Hello,
> > >=20
> > > The attached patch cleans up the too restrictive checks which were
> > > included in the original ptrace/kmod secfix posted by Alan Cox
> > > and applies on top of a clean 2.4.20-rc1 source tree.
> >=20
> > But the ptrace hole is _NOT_ fixed... :(
>=20
> This is the exploit which makes itself suid. Did you leave it suid
> before retesting it?

RIGHT..!!! :) Opps. That's why it "worked"... Never mind. 2.4.20-rc2 is
fixed.

- Adam

--=_courier-945-1052602265-0001-2
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE+vW5c73/bNdaAYUURArOQAKCCZIBTi88vhdDf9fUUnXMYkak16gCgld22
ACIMHEkukZMEHHudnI5g8TM=
=a8lZ
-----END PGP SIGNATURE-----

--=_courier-945-1052602265-0001-2--