6.9
CVE-2011-4945
- EPSS 0.35%
- Veröffentlicht 01.10.2012 23:55:00
- Zuletzt bearbeitet 16.06.2026 23:35:40
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Michael Biebl ≫ Policykit Version0.103
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.268 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
http://secunia.com/advisories/48817
http://security.gentoo.org/glsa/glsa-201204-06.xml
http://cgit.freedesktop.org/PolicyKit/commit/?id=763faf434b445c20ae9529100d3ef5290976d0c9
http://patch-tracker.debian.org/patch/series/view/policykit-1/0.104-2/05_revert-admin-identities-unix-group-wheel.patch
http://www.mail-archive.com/polkit-devel%40lists.freedesktop.org/msg00327.html
http://www.openwall.com/lists/oss-security/2012/03/28/1
http://www.openwall.com/lists/oss-security/2012/03/28/2
https://bugs.gentoo.org/show_bug.cgi?id=401513
https://launchpad.net/ubuntu/+source/policykit-1/0.103-1