FreeBSD procfs Access Control...

- AV AC AU C I A
发布: 2000-12-18
修订: 2025-04-13

procfs is part of the FreeBSD Operating System, maintained by the FreeBSD Project. A problem exists which could allow a user to gain elevated privileges. The problem occurs in the handling of access control in the /proc/<pid>/mem and /proc/<pid>/ctl files. These files provide access to process address space, making it possible to alter the operations of running processes. Abusing the weakness in /proc/<pid>/mem, one could fork() a process from a running process and use it to execute a setuid program. After the execution of the program, the user forking the process still retains read/write access to the memory space, and could use this for the execution of arbitrary code or commands. Therefore, it is possible for a user with malicious intent to abuse this weakness to gain elevated privileges, and potentially administrative privileges.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息