Saturday, December 9, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Privilege escalation due to buffer overflow in glibc

Eliza Houghton by Eliza Houghton
October 4, 2023
in World
0
Privilege escalation due to buffer overflow in glibc
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

In GNU libc, a buffer overflow leads to escalation of privileges for local users. The bug has been fixed and updated packages for major Linux distributions are available.

Advertisement

The libc library is one of the central components of every Linux system and, among other things, provides the functions for dynamically loading other software components. A buffer overflow discovered by security company Qualys now allows attackers to escalate their own privileges and take over a vulnerable Linux system.

Environment variables are popular targets

The buffer overflow can occur when processing the GLIBC_TUNABLES environment variable – as Qualys notes in a detailed analysis, there have been security issues in a similar place in glibc in the past. Using the buffer overflow, the researchers were able to gain root privileges on current Debian, Ubuntu and Fedora systems. The vulnerability is listed as CVE-2023-4911 with a CVSS score of 7.8 and therefore the risk is “high”; Qualys named them “Looney Tunables.”

The dynamic loader ld.so processes data passed by the user, for example from the environment variable GLIBC_TUNABLES, every time it is called. The program code expects parameters in the form tuneable1=wert1:tuneable2=wert2. However, by specifying tuneable1=tuneable2=value, malicious actors can cause a buffer overflow. As a result, they can manipulate the stack, cause SUID programs such as mount to execute code with root privileges and thus take over the system.

The developers of glibc and the affected distributions have already reacted: Updated packages are available for Ubuntu, Debian and RedHat-based Linuxes that fix the gap in the dynamic loader.

(cku)

To the home page
#Privilege #escalation #due #buffer #overflow #glibc

Tags: bufferBuffer OverflowdueescalationGLIBCGNU libclibcoverflowprivilegeSecurity
Previous Post

South American football celebrates a consolation prize by winning the opening of the 2030 World Cup

Next Post

Xavi: “We suffered in the end, but this is the Champions League”

Eliza Houghton

Eliza Houghton

Related Posts

Delfina Gómez, on the Texcaltitlán massacre: “You are not alone, we are with you”
World

Delfina Gómez, on the Texcaltitlán massacre: “You are not alone, we are with you”

by Eliza Houghton
December 9, 2023
Five Gipuzkoan coaches shake up Europe
World

Five Gipuzkoan coaches shake up Europe

by Eliza Houghton
December 9, 2023
Barcelona lineup against Girona: Xavi will repeat eleven against Girona
World

Barcelona lineup against Girona: Xavi will repeat eleven against Girona

by Eliza Houghton
December 9, 2023
40 years of democracy: more than ever
World

40 years of democracy: more than ever

by Eliza Houghton
December 9, 2023
The illustration draws a new youth for the classics
World

The illustration draws a new youth for the classics

by Eliza Houghton
December 9, 2023
Next Post
Xavi: “We suffered in the end, but this is the Champions League”

Xavi: "We suffered in the end, but this is the Champions League"

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

The PSOE takes care of the forms but gives a month of exposure to Feijóo

The PSOE takes care of the forms but gives a month of exposure to Feijóo

August 23, 2023
Peloton’s indoor bikes can now be rented instead of just bought

Peloton’s indoor bikes can now be rented instead of just bought

August 9, 2023
PSOE and Junts agree to hide the name of the verifier to avoid pressure

PSOE and Junts agree to hide the name of the verifier to avoid pressure

November 30, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Europe Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people Politics PSOE Russia Security Spain Sports Sánchez Ukraine United States Updates Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Europe Gaza Gaza Strip Germany Google government Hamas health investiture iOS iPhone Israel law live Madrid Microsoft million news people Politics PSOE Russia Security Spain Sports Sánchez Ukraine United States Updates Vulnerabilities war workshop world years

Recent Posts

  • Delfina Gómez, on the Texcaltitlán massacre: “You are not alone, we are with you”
  • Five Gipuzkoan coaches shake up Europe
  • Barcelona lineup against Girona: Xavi will repeat eleven against Girona
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.