Readline crime: exploiting a SUID logic bug
blog.trailofbits.com | blog | #linux | #privilege-escalation | #exploit | #lateral-movement | #vulnerability-analysis | #suid | #readline | #logic-bug | #environment-variable | #chfn
Summary
A logic bug in readline leaks partial file contents when parsing the INPUTRC environment variable, exploitable via SUID binaries like chfn for lateral movement; reported and patched in February 2022.
- Published
- Collected
Skip to content