PolicyKit 'pkexec' Utility and 'polkitd' Daemon Local Race Condition Vulnerability
BID:47496
Info
PolicyKit 'pkexec' Utility and 'polkitd' Daemon Local Race Condition Vulnerability
| Bugtraq ID: | 47496 |
| Class: | Race Condition Error |
| CVE: |
CVE-2011-1485 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 01 2011 12:00AM |
| Updated: | Apr 16 2015 05:49PM |
| Credit: | David Zeuthen. |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 ARM Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.10 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 LTS Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE openSUSE 11.4 SuSE openSUSE 11.3 Slackware Linux x86_64 -current Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux -current Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Gentoo Linux freedesktop.org PolicyKit 0.96 freedesktop.org PolicyKit 0.7 freedesktop.org PolicyKit 0.6 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
PolicyKit 'pkexec' Utility and 'polkitd' Daemon Local Race Condition Vulnerability
PolicyKit is prone to a local race-condition vulnerability.
A local attacker may exploit this issue to execute arbitrary commands with root privileges.
PolicyKit is prone to a local race-condition vulnerability.
A local attacker may exploit this issue to execute arbitrary commands with root privileges.
Exploit / POC
PolicyKit 'pkexec' Utility and 'polkitd' Daemon Local Race Condition Vulnerability
A working commercial exploit is available for Immunity CANVAS. This exploit is not otherwise publicly available or known to be circulating in the wild.
https://www.immunityinc.com/downloads/immpartners/CVE_2011_1485.tar.gz
The following exploits are available:
A working commercial exploit is available for Immunity CANVAS. This exploit is not otherwise publicly available or known to be circulating in the wild.
https://www.immunityinc.com/downloads/immpartners/CVE_2011_1485.tar.gz
The following exploits are available:
Solution / Fix
PolicyKit 'pkexec' Utility and 'polkitd' Daemon Local Race Condition Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux x86_64 -current
Slackware Linux -current
Slackware Linux 13.1 x86_64
Mandriva Linux Mandrake 2010.1 x86_64
Slackware Linux 13.1
Mandriva Linux Mandrake 2010.1
Solution:
Updates are available. Please see the references for more information.
Slackware Linux x86_64 -current
-
Slackware polkit-0.101-x86_64-2.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ l/polkit-0.101-x86_64-2.txz
Slackware Linux -current
-
Slackware polkit-0.101-i486-2.txz
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/po lkit-0.101-i486-2.txz
Slackware Linux 13.1 x86_64
-
Slackware polkit-1_14bdfd8-x86_64-2_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/package s/polkit-1_14bdfd8-x86_64-2_slack13.1.txz
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva lib64polkit1-devel-0.96-2.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64polkit1_0-0.96-2.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva polkit-0.96-2.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/
Slackware Linux 13.1
-
Slackware polkit-1_14bdfd8-i486-2_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ polkit-1_14bdfd8-i486-2_slack13.1.txz
Mandriva Linux Mandrake 2010.1
-
Mandriva libpolkit1-devel-0.96-2.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libpolkit1_0-0.96-2.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva polkit-0.96-2.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/
References
PolicyKit 'pkexec' Utility and 'polkitd' Daemon Local Race Condition Vulnerability
References:
References:
- Bug 692922 - (CVE-2011-1485) CVE-2011-1485 polkitd/pkexec vulnerability (Red Hat Bugzilla)
- PolicyKit Summary Page (freedesktop.org)