Sinisterly
'Stack Clash' Linux Flaw Enables Root Access - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: General (https://sinister.li/Forum-General)
+--- Forum: World News (https://sinister.li/Forum-World-News)
+--- Thread: 'Stack Clash' Linux Flaw Enables Root Access (/Thread-Stack-Clash-Linux-Flaw-Enables-Root-Access)



'Stack Clash' Linux Flaw Enables Root Access - Ecks - 06-24-2017

Linux, BSD, Solaris and other open source systems are vulnerable to a local privilege escalation vulnerability known as Stack Clash that allows an attacker to execute code at root. Major Linux and open source distributors made patches available Monday, and systems running Linux, OpenBSD, NetBSD, FreeBSD or Solaris on i386 or amd64 hardware should be updated soon.

The risk presented by this flaw, CVE-2017-1000364, becomes elevated especially if attackers are already present on a vulnerable system. They would now be able to chain this vulnerability with other critical issues, including the recently addressed Sudo vulnerability, and then run arbitrary code with the highest privileges, said researchers at Qualys who discovered the vulnerability.

Read More @ https://threatpost.com/stack-clash-vulnerability-in-linux-bsd-systems-enables-root-access/126355/


RE: 'Stack Clash' Linux Flaw Enables Root Access - Inori - 06-24-2017

That's a bit of a scare. Thanks for the info, just updated my kernel with the patch.


RE: 'Stack Clash' Linux Flaw Enables Root Access - Skullmeat - 06-24-2017

"Use linux" they said. "It's safe" they said....


RE: 'Stack Clash' Linux Flaw Enables Root Access - Ecks - 06-24-2017

(06-24-2017, 08:02 PM)Skullmeat Wrote: "Use linux" they said. "It's safe" they said....

Still safer than the alternatives.
[Image: 64929231.jpg]