oss-sec mailing list archives

Re: pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)


From: Matthias Schmidt <oss-sec () xosc org>
Date: Wed, 26 Jan 2022 13:39:29 +0100

Hi,

* Qualys Security Advisory wrote:

Qualys Security Advisory

pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)

This was already mentioned in 2013 in a blog post, however, it seems the
author didn't realize the consequences of their finding:

https://ryiron.wordpress.com/2013/12/16/argv-silliness/

Cheers

        Matthias


Current thread: