Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Not sure whether exploit has been patched #4

Open
cosinekitty opened this issue May 5, 2022 · 2 comments
Open

Not sure whether exploit has been patched #4

cosinekitty opened this issue May 5, 2022 · 2 comments

Comments

@cosinekitty
Copy link

Very interesting video explanation. Thank you! I tried running this on my local Debian system and got this:

$ ./pwnkit
pkexec --version |
       --help |
       --disable-internal-agent |
       [--user username] PROGRAM [ARGUMENTS...]

See the pkexec manual page for more details.
$

So apparently it did not escalate me to root. But I don't think I updated recently enough to be protected. If this is of interest, I can provide more info.

@supaplextor
Copy link

@cosinekitty The prior DSA (Debian Security Announce) is listed. See https://security-tracker.debian.org/tracker/CVE-2021-4034

Use apt-cache policy policykit-1 to see where debs are fetched from and what versions apply.

@omit66
Copy link

omit66 commented Dec 20, 2022

I tried running this using your docker container and I got the same error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants