Major Linux PolicyKit security vulnerability uncovered: Pwnkit
Summary
This time security company Qualys has uncovered a truly dangerous memory corruption vulnerability in polkits pkexec, CVE-2021-4034. Also: This sneaky ransomware is now targeting Linux servers, too Its so dangerous because the program itself is so powerful; its a component for controlling system-wide privileges in Unix-like operating systems. This vulnerability, which has been hiding in plain sight for 12+ years, is a problem with how pkexec reads environmental variables. exists and contains an executable file named "value", then a pointer to the string "name=./value" is written out-of-bounds to envp[0]." But a sophisticated attacker can make a PwnKit assault without leaving any traces in the logs.
Classifications
industries
Aerospace
applications
Business Intelligence
AskAI Classifications
Labels
Operating Systems
Infrastructure Software
DevOps Tools
Linked Companies
Canonical, Ltd.
$50M to $100M
The Fedora Project
$1M to $5M
OpenBSD
$10M to $25M
Qualys, Inc.
$500M to $1B
Oracle
$1B+
Red Hat
$1B+
Involver
$1B+
OpenShift
$1M to $5M