Re: util-linux mount/unmount ASLR bypass via environment variable

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Jan 11, 2018 at 06:51:59PM +0000, halfdog wrote:
> Cleaning up another issue, I noticed that I haven't reported this
> one yet. Debugging of libmount can be activated, also in SUID binaries,

This is expected and wanted ;-)

> thus spilling out the heap addresses.

Good point. Fixed, now for SUIDs it's without the addresses:

$ LIBMOUNT_DEBUG=all mount
18622: libmount:      CXT: ----> allocate [RESTRICTED]
18622: libmount:      TAB: alloc
18622: libmount:    CACHE: alloc
18622: libmount:      TAB: mtab parse: #1 read mountinfo
18622: libmount:      TAB: /proc/self/mountinfo: start parsing [entries=0, filter=not]
18622: libmount:      TAB: add entry: sysfs /sys
18622: libmount:    CACHE: canonicalize path /proc/self/mountinfo
...

Thanks!

   Karel

-- 
 Karel Zak  <kzak@xxxxxxxxxx>
 http://karelzak.blogspot.com
--
To unsubscribe from this list: send the line "unsubscribe util-linux" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Netdev]     [Ethernet Bridging]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux Admin]     [Samba]

  Powered by Linux