Debian Security Update DSA-4428 systemd - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,839
Reaction score
74
Credits
-1,257
Jann Horn discovered that the PAM module in systemd insecurely uses the environment and lacks seat verification permitting spoofing an active session to PolicyKit. A remote attacker with SSH access can take advantage of this issue to gain PolicyKit privileges that are normally only granted to clients in an active session on the local console.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top