Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-2238

Опубликовано: 04 июн. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-2238: polkit security update (IMPORTANT)

[0.115-11.0.1]

  • Increase timeout to avoid defunct processes [Orabug: 26930744]

[0.115-11.1]

  • early disconnection from D-Bus results in privilege esc.
  • Resolves: CVE-2021-3560

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

polkit

0.115-11.0.1.el8_4.1

polkit-devel

0.115-11.0.1.el8_4.1

polkit-docs

0.115-11.0.1.el8_4.1

polkit-libs

0.115-11.0.1.el8_4.1

Oracle Linux x86_64

polkit

0.115-11.0.1.el8_4.1

polkit-devel

0.115-11.0.1.el8_4.1

polkit-docs

0.115-11.0.1.el8_4.1

polkit-libs

0.115-11.0.1.el8_4.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
redhat
около 4 лет назад

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
nvd
больше 3 лет назад

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
debian
больше 3 лет назад

It was found that polkit could be tricked into bypassing the credentia ...

suse-cvrf
почти 4 года назад

Security update for polkit