Bug#607370: linux-image-2.6.32-5-amd64: exploit for x86_64 linux kernel ia32syscall emulation still works

2010-12-17 Thread Travis Thompson
Package: linux-2.6
Version: 2.6.32-29
Severity: important

An older explot based off of CVE-2010-3301 still works or works again on
current amd64 kernel for debian testing.
http://www.exploit-db.com/exploits/15023/ this code currently can root
my computer.


-- Package-specific info:
** Version:
Linux version 2.6.32-5-amd64 (Debian 2.6.32-29) (b...@decadent.org.uk) (gcc 
version 4.3.5 (Debian 4.3.5-4) ) #1 SMP Fri Dec 10 15:35:08 UTC 2010

** Command line:
BOOT_IMAGE=/boot/vmlinuz-2.6.32-5-amd64 
root=UUID=560932ec-b2af-424b-b93d-98675b13508e ro quiet

** Tainted: P (1)
 * Proprietary module has been loaded.

** Kernel log:
[3.072272] ACPI: SSDT cfee8440 00152 (v01  PmRef  Cpu1Ist 3000 
INTL 20041203)
[3.072379] processor LNXCPU:01: registered as cooling_device1
[3.116750] input: PC Speaker as /devices/platform/pcspkr/input/input5
[3.166371] usb 5-1.1: New USB device found, idVendor=045e, idProduct=0289
[3.166373] usb 5-1.1: New USB device strings: Mfr=0, Product=0, 
SerialNumber=0
[3.166430] usb 5-1.1: configuration #1 chosen from 1 choice
[3.227153] input: Power Button as 
/devices/LNXSYSTM:00/LNXSYBUS:00/PNP0C0C:00/input/input6
[3.227175] ACPI: Power Button [PWRB]
[3.227225] input: Power Button as 
/devices/LNXSYSTM:00/LNXPWRBN:00/input/input7
[3.227243] ACPI: Power Button [PWRF]
[3.283059] input: Microsoft X-Box pad v2 (US) as 
/devices/pci:00/:00:1a.2/usb5/5-1/5-1.1/5-1.1:1.0/input/input8
[3.283117] usbcore: registered new interface driver xpad
[3.283119] xpad: X-Box pad driver
[3.402232] i801_smbus :00:1f.3: PCI INT B - GSI 18 (level, low) - IRQ 
18
[4.026280] nvidia: module license 'NVIDIA' taints kernel.
[4.026283] Disabling lock debugging due to kernel taint
[4.522996] nvidia :01:00.0: PCI INT A - GSI 16 (level, low) - IRQ 16
[4.523002] nvidia :01:00.0: setting latency timer to 64
[4.523005] vgaarb: device changed decodes: 
PCI::01:00.0,olddecodes=io+mem,decodes=none:owns=io+mem
[4.523190] NVRM: loading NVIDIA UNIX x86_64 Kernel Module  260.19.29  Wed 
Dec  8 12:08:56 PST 2010
[4.714049] Linux video capture interface: v2.00
[4.791669] cx88/2: cx2388x MPEG-TS Driver Manager version 0.0.7 loaded
[4.792185] cx88[0]: subsystem: 7063:5500, board: pcHDTV HD5500 HDTV 
[card=47,autodetected], frontend(s): 1
[4.792187] cx88[0]: TV tuner type 64, Radio tuner type -1
[4.793119] cx88/0: cx2388x v4l2 driver version 0.0.7 loaded
[4.861501] cx2388x alsa driver version 0.0.7 loaded
[5.105907] tuner 1-0043: chip found @ 0x86 (cx88[0])
[5.113025] tda9887 1-0043: creating new instance
[5.113026] tda9887 1-0043: tda988[5/6/7] found
[5.115405] tuner 1-0061: chip found @ 0xc2 (cx88[0])
[5.155719] tuner-simple 1-0061: creating new instance
[5.155721] tuner-simple 1-0061: type set to 64 (LG TDVS-H06xF)
[5.158581] input: cx88 IR (pcHDTV HD5500 HDTV) as 
/devices/pci:00/:00:1e.0/:02:04.2/input/input9
[5.158615] cx88[0]/2: cx2388x 8802 Driver Manager
[5.158626] cx88-mpeg driver manager :02:04.2: PCI INT A - GSI 23 
(level, low) - IRQ 23
[5.158630] cx88-mpeg driver manager :02:04.2: setting latency timer to 
64
[5.158635] cx88[0]/2: found at :02:04.2, rev: 5, irq: 23, latency: 64, 
mmio: 0xfa00
[5.158638] IRQ 23/cx88[0]: IRQF_DISABLED is not guaranteed on shared IRQs
[5.158674] cx8800 :02:04.0: PCI INT A - GSI 23 (level, low) - IRQ 23
[5.158680] cx88[0]/0: found at :02:04.0, rev: 5, irq: 23, latency: 20, 
mmio: 0xf800
[5.158687] IRQ 23/cx88[0]: IRQF_DISABLED is not guaranteed on shared IRQs
[5.158712] cx88[0]/0: registered device video0 [v4l2]
[5.158728] cx88[0]/0: registered device vbi0
[5.161062] C-Media PCI :02:03.0: PCI INT A - GSI 22 (level, low) - 
IRQ 22
[5.161079] C-Media PCI :02:03.0: setting latency timer to 64
[5.161798] cx88_audio :02:04.1: PCI INT A - GSI 23 (level, low) - IRQ 
23
[5.161802] cx88_audio :02:04.1: setting latency timer to 64
[5.161805] IRQ 23/cx88[0]: IRQF_DISABLED is not guaranteed on shared IRQs
[5.161817] cx88[0]/1: CX88x/0: ALSA support for cx2388x boards
[5.188251] cx88/2: cx2388x dvb driver version 0.0.7 loaded
[5.188253] cx88/2: registering cx8802 driver, type: dvb access: shared
[5.188256] cx88[0]/2: subsystem: 7063:5500, board: pcHDTV HD5500 HDTV 
[card=47]
[5.188257] cx88[0]/2: cx2388x based DVB/ATSC card
[5.188258] cx8802_alloc_frontends() allocating 1 frontend(s)
[5.537211] tuner-simple 1-0061: attaching existing instance
[5.537213] tuner-simple 1-0061: type set to 64 (LG TDVS-H06xF)
[5.537247] tda9887 1-0043: attaching existing instance
[5.537250] DVB: registering new adapter (cx88[0])
[5.537252] DVB: registering adapter 0 frontend 0 (LG Electronics LGDT3303 
VSB/QAM Frontend)...
[6.124624] loop: module loaded
[6.192123] usb-storage: device scan complete

Bug#607370: linux-image-2.6.32-5-amd64: exploit for x86_64 linux kernel ia32syscall emulation still works

2010-12-17 Thread dann frazier
On Fri, Dec 17, 2010 at 09:22:16AM -0500, Travis Thompson wrote:
 Package: linux-2.6
 Version: 2.6.32-29
 Severity: important
 
 An older explot based off of CVE-2010-3301 still works or works again on
 current amd64 kernel for debian testing.
 http://www.exploit-db.com/exploits/15023/ this code currently can root
 my computer.

I just did a fresh install of squeeze and I cannot reproduce. Are you
sure the shell the exploit gives you is a *root* shell?




-- 
To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20101217170802.gc26...@dannf.org