oss-sec mailing list archives

What is the "Grinch" polkit/wheel group issue?


From: Marcus Meissner <meissner () suse de>
Date: Wed, 17 Dec 2014 18:00:09 +0100

Hi,

This probably needs a CVE too, or does it have one?

https://www.alertlogic.com/blog/dont-let-grinch-steal-christmas/
http://www.pcworld.com/article/2860032/this-linux-grinch-could-put-a-hole-in-your-security-stocking.html

Although it seems that the user is in the "wheel" group for this to be exploitable
and is hard to specify what actions should be safed by another query or which should not.

Ciao, Marcus


Current thread: