2016年12月23日 星期五

Linux kernel: Dirty COW (CVE-2016-5195)


REF: https://github.com/dirtycow/dirtycow.github.io/wiki/VulnerabilityDetails

Explaining dirtyc0w local root exploit - CVE-2016-5195

Impact

  • An unprivileged local user could use this flaw to gain write access to otherwise read-only memory mappings and thus increase their privileges on the system.
  • This flaw allows an attacker with a local system account to modify on-disk binaries, bypassing the standard permission mechanisms that would prevent modification without an appropriate permission set.

沒有留言:

張貼留言