Blog | G5 Cyber Security

Warning! Unprivileged Linux Users With UID > INT_MAX Can Execute Any Command

Vulnerability resides in PolicyKit, an application-level toolkit for Unix-like operating systems. The vulnerability exists due to PolicyKit’s improper validation of permission requests for any low-privileged user with UID greater than INT_MAX. Red Hat has recommended system administrators not to allow any negative UIDs or UIDs greater than 2147483646 in order to mitigate the issue until the patch is released. The issue, tracked as CVE-2018-19788, impacts PolicyKit version 0.115 which comes pre-installed on most popular Linux distributions.

Source: https://thehackernews.com/2018/12/linux-user-privilege-policykit.html

Exit mobile version