Unspecified vulnerability in the expand_stack function in grsecurity PaX allows...
Vulnerability Description
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities." The developer also cites a past disclosure that was not proven. As of 20070120, the original researcher has released demonstration code
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0257
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securitytracker.com/id?1017509
- http://www.digitalarmaments.com/pre2007-00018659.html
- http://www.securityfocus.com/archive/1/456626/100/0/threaded
- http://www.securityfocus.com/archive/1/456722/100/0/threaded
- http://www.securityfocus.com/archive/1/462302/100/100/threaded
- http://www.digitalarmaments.com/news_news.shtml
- http://grsecurity.net/news.php#digitalfud
- http://secunia.com/advisories/23713
- http://www.securityfocus.com/bid/22014
- http://forums.grsecurity.net/viewtopic.php?t=1646
- http://www.securityfocus.com/archive/1/457509/100/0/threaded
- http://www.vupen.com/english/advisories/2007/0155
- http://osvdb.org/32727
More from grsecurity
View All →Affected Vendor
grsecurity
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.