Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726)
We discovered a Local Privilege Escalation in OpenBSD's dynamic loader (ld.so): this vulnerability is exploitable in the default installation (via the set-user-ID executable chpass or passwd) and yields full root privileges.
We developed a simple proof of concept and successfully tested it against OpenBSD 6.6 (the current release), 6.5, 6.2, and 6.1, on both amd64 and i386; other releases and architectures are probably also exploitable.
https://www.openwall.com/lists/oss-security/2019/12/11/9
#security
Post #95
845