漏洞信息详情
polkit 权限许可和访问控制问题漏洞
漏洞简介
polkit是一个在类 Unix操作系统中控制系统范围权限的组件。通过定义和审核权限规则,实现不同优先级进程间的通讯。
polkit 存在安全漏洞,该漏洞源于当请求进程在调用polkit_system_bus_name_get_creds_sync之前断开与dbus-daemon的连接时,该进程无法获得进程的唯一uid和pid,也无法验证请求进程的特权。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://gitlab.freedesktop.org/polkit/polkit/
参考网址
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060718
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/polkit-privilege-escalation-via-polkit-system-bus-name-get-creds-sync-35615
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1928
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/165088/Polkit-Authentication-Bypass-Local-Privilege-Escalation.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060912
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163452/Polkit-D-Bus-Authentication-Bypass.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021071314
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2657
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163142/Polkit-0.105-26-0.117-2-Privilege-Escalation.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2711
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1940
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2320
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163400/Red-Hat-Security-Advisory-2021-2555-01.html
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/50011
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-3560
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021062312
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021070616
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2201
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162940/Red-Hat-Security-Advisory-2021-2236-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163488/Gentoo-Linux-Security-Advisory-202107-31.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163242/Red-Hat-Security-Advisory-2021-2522-01.html
受影响实体
暂无
补丁
- polkit 权限许可和访问控制问题漏洞的修复措施<!--2021-6-3-->
还没有评论,来说两句吧...