Gentoo Archives: gentoo-hardened

From: pageexec@××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] 2.6.27-hardened-r8: assassination
Date: Fri, 06 Mar 2009 22:13:30
Message-Id: 49B19FEB.13855.19525701@pageexec.freemail.hu
In Reply to: Re: [gentoo-hardened] 2.6.27-hardened-r8: assassination by Alex Efros
1 On 6 Mar 2009 at 23:51, Alex Efros wrote:
2
3 > When I run apache for the first time after reboot - without strace/core,
4 > just to see is it crash - I got this in kernel log:
5 >
6 > 2009-03-06_20:48:56.60108 kern.info: apache2[4621]: segfault at
7 > 4d554ed0 ip 4d541399 sp 594130d0 error 7 in ld-2.6.1.so[4d53a000+1a000]
8
9 ah crap, i know what it is. it's a several years old glibc bug where someone
10 put a certain variable into the RELRO segment but forgot that it'll be written
11 to later when a library with RWE GNU_STACK is loaded. the workaround is to find
12 that library (just extract them from strace, probably it'll be pari's library)
13 and run execstack -c on it.

Replies

Subject Author
Re: [gentoo-hardened] 2.6.27-hardened-r8: assassination Alex Efros <powerman@××××××××××××××××××.com>