Re: [nexa] A bug lurking for 12 years gives attackers root on most major Linux distros

2022-01-27 Thread Giacomo Tesio
Ciao Giovanni, On January 27, 2022 5:52:25 PM UTC, "380°" wrote: > > Insomma non temete: dopo 12 anni dalla sua introduzione, questa > > vulnerabilità > > è stata corretta entro poche ore dalla propria diffusione pubblica. > > ...mentre dopo 50 anni dall'introduzione del C sarà ancora possibile

Re: [nexa] A bug lurking for 12 years gives attackers root on most major Linux distros

2022-01-27 Thread 380°
Buongiorno Giacomo, Giacomo Tesio writes: [...] > Attackers who already have a toehold on a vulnerable machine can abuse > the vulnerability to ensure a malicious payload or command runs with the > highest system rights available. proprio per non sminuire la portata del bug, direi che la fr

[nexa] A bug lurking for 12 years gives attackers root on most major Linux distros

2022-01-27 Thread Giacomo Tesio
Since 2009, pkexec has contained a memory-corruption vulnerability that people with limited control of a vulnerable machine can exploit to escalate privileges all the way to root. Exploiting the flaw is trivial and, by some accounts, 100 percent reliable. Attackers who already have a toehold o