PolicyKit 'pkexec' File Existence Information Disclosure Weakness
BID:39198
Info
PolicyKit 'pkexec' File Existence Information Disclosure Weakness
| Bugtraq ID: | 39198 |
| Class: | Unknown |
| CVE: |
CVE-2010-0750 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 05 2010 12:00AM |
| Updated: | Apr 18 2012 05:50PM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.10 sparc Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu Ubuntu Linux 8.10 lpia Ubuntu Ubuntu Linux 8.10 i386 Ubuntu Ubuntu Linux 8.10 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Gentoo Linux freedesktop.org PolicyKit 0.96 |
| Not Vulnerable: | |
Discussion
PolicyKit 'pkexec' File Existence Information Disclosure Weakness
PolicyKit is prone to an information-disclosure weakness in the 'pkexec' utility.
An attacker can exploit this issue to access sensitive information that may aid in further attacks.
PolicyKit 0.96 is vulnerable; other versions may also be affected.
PolicyKit is prone to an information-disclosure weakness in the 'pkexec' utility.
An attacker can exploit this issue to access sensitive information that may aid in further attacks.
PolicyKit 0.96 is vulnerable; other versions may also be affected.
Exploit / POC
PolicyKit 'pkexec' File Existence Information Disclosure Weakness
A local attacker uses standard tools to exploit this issue.
A local attacker uses standard tools to exploit this issue.
Solution / Fix
PolicyKit 'pkexec' File Existence Information Disclosure Weakness
Solution:
Updates have been committed to the application's git repository. Please see the references for more information.
Solution:
Updates have been committed to the application's git repository. Please see the references for more information.
References
PolicyKit 'pkexec' File Existence Information Disclosure Weakness
References:
References:
- pkexec information disclosure vulnerability (Dan Rosenberg)
- Bug 26982 �?? pkexec information disclosure vulnerability (Dan Rosenberg)
- PolicyKit Homepage (freedesktop.org)