CVE-2011-1485
Linux PolicyKit - Race Condition Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
CondiciĆ³n de carrera en la utilidad pkexec y el demonio polkitd de PolicyKit (polkit) 0.96. Permite a usuarios locales escalar privilegios ejecutando un programa setuid desde pkexec. Relacionado con el uso del ID de usuario efectivo en vez del real.
A race condition flaw was found in the PolicyKit pkexec utility and polkitd daemon. A local user could use this flaw to appear as a privileged user to pkexec, allowing them to execute arbitrary commands as root by running those commands with pkexec. Those vulnerable include RHEL6 prior to polkit-0.96-2.el6_0.1 and Ubuntu libpolkit-backend-1 prior to 0.96-2ubuntu1.1 (10.10) 0.96-2ubuntu0.1 (10.04 LTS) and 0.94-1ubuntu1.1 (9.10).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-03-21 CVE Reserved
- 2011-04-20 CVE Published
- 2011-10-05 First Exploit
- 2024-07-31 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/48817 | Third Party Advisory | |
http://securityreason.com/securityalert/8424 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35021 | 2014-10-20 | |
https://www.exploit-db.com/exploits/17942 | 2011-10-08 | |
https://www.exploit-db.com/exploits/17932 | 2011-10-05 | |
https://github.com/Pashkela/CVE-2011-1485 | 2013-06-16 |
URL | Date | SRC |
---|---|---|
http://security.gentoo.org/glsa/glsa-201204-06.xml | 2012-12-19 | |
http://www.debian.org/security/2011/dsa-2319 | 2012-12-19 | |
http://www.mandriva.com/security/advisories?name=MDVSA-2011:086 | 2012-12-19 | |
http://www.redhat.com/support/errata/RHSA-2011-0455.html | 2012-12-19 | |
http://www.ubuntu.com/usn/USN-1117-1 | 2012-12-19 | |
https://access.redhat.com/security/cve/CVE-2011-1485 | 2011-04-19 |