Reply
Thread Tools
Posts: 281 | Thanked: 679 times | Joined on Feb 2010
#1
http://cve.mitre.org/cgi-bin/cvename...=CVE-2009-1185 describes that it is possible to get root priviledges from user space by tricking udev < 1.4.1.

The PR 1.2 udev is 0.125-7+142.maemo1+0m5 (definitely < 1.4.1??).

So: is it possible to hack the system? Are updates of udev possible? How would Nokia react about generic linux vulnerabilities in future?
 
dchky's Avatar
Posts: 549 | Thanked: 299 times | Joined on Jun 2010 @ Australian in the Philippines
#2
Serious question, or statement if you will: Does it really matter?

As you said, this is a local exploit. Physical access to the N900 means your data is compromised anyway. I treat my phone like I treat my wallet : ) Nobody touches it except for me. Aside from this, one need only install rootsh, no password required, and you have full system access anyway.
 
Posts: 145 | Thanked: 237 times | Joined on Mar 2010 @ Helsinki
#3
Originally Posted by dchky View Post
Serious question, or statement if you will: Does it really matter?

As you said, this is a local exploit. Physical access to the N900 means your data is compromised anyway. I treat my phone like I treat my wallet : ) Nobody touches it except for me. Aside from this, one need only install rootsh, no password required, and you have full system access anyway.
Local privilege escalation vulnerabilities can be dangerous even remotely.

Let's say you have a chrooted browser that's running under a different user. You'd feel pretty safe from any security problems in the browser, right? If the attacker can also gain root, you're not.
 
Posts: 281 | Thanked: 679 times | Joined on Feb 2010
#4
This vulnerability is a problem with Android smartphones. There is an app which looks like a coool wallpaper collection (downloaded very often). This app uses the vulnerability to send sensitive data home (to china). Source blackhat/Spiegel http://www.spiegel.de/netzwelt/web/0...9355-3,00.html (german, sorry), http://g3la.de/37 and others. The app works lokal :-(
 

The Following User Says Thank You to cy8aer For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 09:53.