This Linux grinch could put a hole in your security stocking

Discussion in 'other security issues & news' started by ronjor, Dec 16, 2014.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,054
    Location:
    Texas
  2. Gullible Jones

    Gullible Jones Registered Member

    Joined:
    May 16, 2013
    Posts:
    1,466
    The article is not just content free, it's flat wrong. This is a local privilege escalation hole, not remote; and it's in Polkit, not a kernel component. The original blog post explains it well though:

    https://www.alertlogic.com/blog/dont-let-grinch-steal-christmas/

    I can't say I'm surprised though, Polkit always struck me as hugely overcomplicated and untrustworthy.
     
  3. 142395

    142395 Guest

    Thanks for explanation GJ, perfect example to indicate that you had better look for primary source when the title is sensational.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.