PT-2011-1020 · Policykit+3 · Polkit+3

Neel Mehta

·

Published

2011-04-19

·

Updated

2012-12-19

·

CVE-2011-1485

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions polkit versions prior to 0.104-r1 policykit-1 versions prior to 0.104-r1
Description The issue affects the polkit package in Gentoo Linux and policykit-1 in Debian GNU/Linux, allowing local exploitation that may lead to breaches in confidentiality, integrity, and availability of protected information. A race condition in the pkexec utility and polkitd daemon in PolicyKit allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
Recommendations For polkit versions prior to 0.104-r1, update to version 0.104-r1 or later to resolve the issue. For policykit-1 versions prior to 0.104-r1, update to version 0.104-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pkexec utility and polkitd daemon to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01460
BDU:2015-09652
CVE-2011-1485
DSA-2319-1
OPENSUSE-SU-2024:10436-1
RHSA-2011:0455
RHSA-2011_0455

Affected Products

Red Hat
Pkexec
Policykit-1
Polkit