Forums

Skip to content

  • Quick links
  • FAQ
  • Login
  • Register
  • Board index Assistance News & Announcements

[ GLSA 202201-01 ] Polkit

Read this before submitting your first post to any forum
Post Reply
1 post • Page 1 of 1
Author
Message
GLSA
Advocate
Advocate
Posts: 2663
Joined: Wed May 12, 2004 4:41 pm

[ GLSA 202201-01 ] Polkit

  • Quote

Post by GLSA » Thu Jan 27, 2022 6:26 am

Gentoo Linux Security Advisory

Title: Polkit: Local privilege escalation ([glsa=202201-01]GLSA 202201-01[/glsa])
Severity: high
Exploitable: local
Date: 2022年01月27日
Bug(s): #832057
ID: 202201-01

Synopsis

A vulnerability in polkit could lead to local root privilege escalation.


Background

polkit is a toolkit for managing policies related to unprivileged processes communicating with privileged process.

Affected Packages

Package: sys-auth/polkit
Vulnerable: < 0.120-r2
Unaffected: >= 0.120-r2
Architectures: All supported architectures


Description

Flawed input validation of arguments was discovered in the 'pkexec' program's main() function.

Impact

A local attacker could achieve root privilege escalation.

Workaround

Run the following command as root:
# chmod 0755 /usr/bin/pkexec

Resolution

Upgrade Polkit to a patched version.

Code: Select all

# emerge --sync
			# emerge --ask --verbose ">=sys-auth/polkit-0.120-r2"


References

CVE-2021-4034
Last edited by GLSA on Tue Feb 01, 2022 4:17 am, edited 1 time in total.
Top
Post Reply
1 post • Page 1 of 1

Return to "News & Announcements"

Jump to
  • Assistance
  • ↳ News & Announcements
  • ↳ Installing Gentoo
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Authors
Gentoo is a trademark of the Gentoo Foundation, Inc. and of Förderverein Gentoo e.V.
The contents of this document, unless otherwise expressly stated, are licensed under the CC-BY-SA-4.0 license.
The Gentoo Name and Logo Usage Guidelines apply.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

AltStyle によって変換されたページ (->オリジナル) /