Hacker News
new
past
comments
ask
show
jobs
points
by
tptacek
14 hours ago
|
comments
by
cperciva
13 hours ago
|
next
[-]
I don't think so? It's a buffer overflow in the system call.
reply
by
tptacek
13 hours ago
|
parent
|
[-]
I just read that it was spilling into argv or something and assumed the vector was somehow injecting arguments or something.
reply
by
cperciva
12 hours ago
|
parent
|
[-]
The exploit is injecting environment variables, but yes, close enough. You need someone to call execve as root in order to become root, but you don't need a setuid binary.
reply
by
cryptbe
6 hours ago
|
prev
|
[-]
[dead]
reply