CVE-2009-0343 – Systrace 1.x (Linux Kernel x64) - Aware Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2009-0343
Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes. Niels Provos Systrace v1.6f y anteriores en las plataformas Linux x86_64 permite a usuarios locales evitar las restricciones de acceso previstas, mediante una syscal de 32 bit, con un número correspondiente a una llamada de 64 bit. Relacionada con las condiciones de carrera en la monitorización de procesos de 64 bit. • https://www.exploit-db.com/exploits/32751 http://scary.beasts.org/security/CESA-2009-001.html http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html http://www.citi.umich.edu/u/provos/systrace http://www.securityfocus.com/archive/1/500377/100/0/threaded http://www.securityfocus.com/bid/33417 • CWE-264: Permissions, Privileges, and Access Controls •