Количество 25
Количество 25
BDU:2022-00488
Уязвимость библиотеки Polkit и инструмента песочницы Bubblewrap, вызванная переполнением буфера на стеке, позволяющая нарушителю повысить свои привилегии до уровня суперпользователя
ROS-20220301-01
Уязвимость инструмента песочницы Bubblewrap
ROS-20220128-01
Уязвимость библиотеки Polkit
ALT-PU-2022-1811
ALT-PU-2022-1811: package `systemd` update to version 249.11-alt1
ALT-PU-2022-1346
ALT-PU-2022-1346: package `systemd` update to version 249.10-alt1
ALT-PU-2022-1140
ALT-PU-2022-1140: package `polkit` update to version 0.120-alt1.qa1
ALT-PU-2022-1139
ALT-PU-2022-1139: package `polkit` update to version 0.120-alt1.qa1
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexe ...
openSUSE-SU-2022:0190-1
Security update for polkit
SUSE-SU-2022:0191-1
Security update for polkit
SUSE-SU-2022:0190-1
Security update for polkit
SUSE-SU-2022:0189-1
Security update for polkit
RLSA-2022:267
Important: polkit security update
RLSA-2022:0267
Important: polkit security update
GHSA-qgr2-xgqv-24x8
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
ELSA-2022-9073
ELSA-2022-9073: polkit security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2022-00488 Уязвимость библиотеки Polkit и инструмента песочницы Bubblewrap, вызванная переполнением буфера на стеке, позволяющая нарушителю повысить свои привилегии до уровня суперпользователя | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
ROS-20220301-01 Уязвимость инструмента песочницы Bubblewrap | 94% Критический | больше 4 лет назад | ||
ROS-20220128-01 Уязвимость библиотеки Polkit | 94% Критический | больше 4 лет назад | ||
ALT-PU-2022-1811 ALT-PU-2022-1811: package `systemd` update to version 249.11-alt1 | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
ALT-PU-2022-1346 ALT-PU-2022-1346: package `systemd` update to version 249.10-alt1 | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
ALT-PU-2022-1140 ALT-PU-2022-1140: package `polkit` update to version 0.120-alt1.qa1 | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
ALT-PU-2022-1139 ALT-PU-2022-1139: package `polkit` update to version 0.120-alt1.qa1 | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
CVE-2021-4034 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
CVE-2021-4034 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
CVE-2021-4034 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
CVE-2021-4034 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
CVE-2021-4034 A local privilege escalation vulnerability was found on polkit's pkexe ... | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
openSUSE-SU-2022:0190-1 Security update for polkit | 94% Критический | больше 4 лет назад | ||
SUSE-SU-2022:0191-1 Security update for polkit | 94% Критический | больше 4 лет назад | ||
SUSE-SU-2022:0190-1 Security update for polkit | 94% Критический | больше 4 лет назад | ||
SUSE-SU-2022:0189-1 Security update for polkit | 94% Критический | больше 4 лет назад | ||
RLSA-2022:267 Important: polkit security update | 94% Критический | больше 4 лет назад | ||
RLSA-2022:0267 Important: polkit security update | 94% Критический | больше 4 лет назад | ||
GHSA-qgr2-xgqv-24x8 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine. | CVSS3: 7.8 | 94% Критический | больше 4 лет назад | |
ELSA-2022-9073 ELSA-2022-9073: polkit security update (IMPORTANT) | 94% Критический | больше 4 лет назад |
Уязвимостей на страницу