oss-sec mailing list archives
What is the "Grinch" polkit/wheel group issue?
From: Marcus Meissner <meissner () suse de>
Date: Wed, 17 Dec 2014 18:00:09 +0100
Hi, This probably needs a CVE too, or does it have one? https://www.alertlogic.com/blog/dont-let-grinch-steal-christmas/ http://www.pcworld.com/article/2860032/this-linux-grinch-could-put-a-hole-in-your-security-stocking.html Although it seems that the user is in the "wheel" group for this to be exploitable and is hard to specify what actions should be safed by another query or which should not. Ciao, Marcus
Current thread:
- What is the "Grinch" polkit/wheel group issue? Marcus Meissner (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Elad Alfassa (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Todd C. Miller (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Nicolas Vigier (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Daniel Kahn Gillmor (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Kurt Seifried (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Dean Pierce (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Grandma Eubanks (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Daniel Micay (Dec 17)
- Re: What is the "Grinch" polkit/wheel group issue? Dean Pierce (Dec 17)