LIDS Capability Leakage via...

- AV AC AU C I A
发布: 2002-01-09
修订: 2025-04-13

LIDS ("Linux Intrusion Detection System") is a kernel add-on that implements enhanced filesystem access control and other security features. LIDS also enhances the Linux 'capabilities' security mechanism, which allows for system utilities to perform specific administrative operations without full superuser privileges. It is possible for attackers to gain capabilities of other programs by executing custom code using the LD_PRELOAD environment variable. LD_PRELOAD is an environment variable that lists shared libraries that are to be loaded in programs at runtime. Attackers can execute code with the capabilities of any program by linking a custom library to the target program via LD_PRELOAD. This vulnerability allows for security policy to be violated. Attackers who have obtained root access may gain the capabilities assigned to any program. In addition, local users may be able to elevate privileges by exploiting non-setuid programs assigned the CAP_SETUID capability.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息