berdav / CVE-2021-4034

CVE-2021-4034 1day
MIT License
1.94k stars 508 forks source link

Fix for versions where GIO_USE_VFS is set to local #15

Closed synap5e closed 2 years ago

synap5e commented 2 years ago

This was required to make this work on my version of pkexec.

Credit to https://github.com/PeterGottesman/pwnkit-exploit

berdav commented 2 years ago

Nice!

Which systems reset this value?

Merged. :)

synap5e commented 2 years ago

Looks like anything with polkit 0.114 or newer https://twitter.com/wdormann/status/1486813200100245515

My system was arch, and I also tested the exploit out in an ubuntu docker containers after installing polkit with the apt sources set to fetch a dec 2021 version, and that system also required this patch.