|
|
| |
|
| |
gksu-polkit: root privilege escalation
| Package(s): | gksu-polkit |
CVE #(s): | CVE-2012-5617
|
| Created: | March 7, 2013 |
Updated: | March 13, 2013 |
| Description: |
From the Red Hat Bugzilla entry:
Miroslav Trmac reported that gksu-polkit ships with an extremely permissive PolicyKit policy configuration file. Because gksu-polkit allows a user to execute a program with administrative privileges, and because the default allow_active setting is "auth_self" rather than "auth_admin", any local user can use gksu-polkit to execute arbitrary programs (like a bash shell) with root privileges. |
| Alerts: |
|
( Log in to post comments)
|
|
|