SB2011042002 - Slackware Linux update for polkit
Published: April 20, 2011 Updated: May 6, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2011-1485)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
Remediation
Install update from vendor's website.