oss-sec mailing list archives

Re: What is the "Grinch" polkit/wheel group issue?


From: Elad Alfassa <elad () fedoraproject org>
Date: Wed, 17 Dec 2014 19:15:10 +0200

This is not a vulnerability, this is expected behaviour.

On Wed, Dec 17, 2014 at 7:00 PM, Marcus Meissner <meissner () suse de> wrote:

Hi,

This probably needs a CVE too, or does it have one?

https://www.alertlogic.com/blog/dont-let-grinch-steal-christmas/

http://www.pcworld.com/article/2860032/this-linux-grinch-could-put-a-hole-in-your-security-stocking.html

Although it seems that the user is in the "wheel" group for this to be
exploitable
and is hard to specify what actions should be safed by another query or
which should not.

Ciao, Marcus



-- 
-Elad Alfassa.

Current thread: