4 ms·
The piece of polkit that this exploits was blogged about in 2013: https://ryiron.wordpress.com/2013/12/16/argv-silliness/ https://ryiron.wordpress.com/2013/12/1
by mwarkentin 5y ago
The piece of polkit that this exploits was blogged about in 2013: https://ryiron.wordpress.com/2013/12/16/argv-silliness/ https://ryiron.wordpress.com/2013/12/16/argv-silliness/
- tyingq 5y agoGreat find...so they gave up at "However, because we can’t pass any option arguments, the executing user will default to root, which presumably we don’t have the password for." It seems possible the current exploit authors read this and picked up from there..."what else could we do given that we can't pass options?"
- noobermin 5y agoIf this was known in 2013 why wasn't it fixed? This is literally a simple error in parsing program arguments.
- dc-programmer 5y agoThis is the dark side of risk based security which often manifests. The code gets audited over a day or two and items get ranked by severity. The “minor” bugs are fixed much later if never and it’s ok because they are low severity. But if you pull on the threads of minor issues there are usually deeper issues at play. Further bugs might be minor if considered independently, but can be chained together to perform severe exploits. Given the resources, I think the best approach is to just aggressively eliminate all known undefined behavior in a application