You are not logged in.
Pages: 1
Slashdot has posted a story about a major flaw in PolicyKit, a widely used SUID utility in many Linux distributions. The arguments in the comments started quickly about whether this is a "systemd specific" problem.
https://linux.slashdot.org/story/22/01/ … red-pwnkit
So, is it really a systemd specific problem? Is PolicyKit found in Devuan or other distros that do not use systemd? In other words will there be a patch for Devuan?
Offline
don't know mch about policykit, but it can't be a systemd issue... buggy pkexec binary was present since it was introduced back in 2009. (long before systemd entered debian).. so i'd say nothing to do with systemd.
and devuan is already patched, just upgrade..: https://bugs.devuan.org/cgi/bugreport.cgi?bug=658
Offline
Technical explanation here:
https://blog.qualys.com/vulnerabilities … -2021-4034
Of particular note:
we note that OpenBSD is not exploitable, because its kernel refuses to execve() a program if argc is 0
Puffy ftw!
Anyway it's only a local vulnerability with a severity of 7.8. Ho hum.
EDIT:
is it really a systemd specific problem?
Nope.
As noted above OpenBSD has polkit but that OS is fundamentally incompatible with systemd, as is Alpine Linux.
Last edited by Head_on_a_Stick (2022-01-26 20:43:03)
Brianna Ghey — Rest In Power
Offline
Hello:
... only a local vulnerability with a severity of 7.8.
Update available as of early afternoon -03:00 GMT.
Go Devuan !
BTW:
-----------------------------------------------------------------------------------------------------------------------------------
To obtain a root shell use su -. Using just su will result in "command not found" messages.
-----------------------------------------------------------------------------------------------------------------------------------
The slickest stiky I've seen yet. 8^D
Best,
A.
Last edited by Altoid (2022-01-26 23:10:21)
Offline
I read that too. Thank you for the updates today :-)
pic from 1993, new guitar day.
Offline
Good piece from Ariadne about this:
Brianna Ghey — Rest In Power
Offline
Pages: 1