GLSA-202201-01 : Polkit: Local privilege escalation

high Nessus Plugin ID 157140

Version 1.6

Nov 17, 2023, 3:11 PM

  • CVSS metrics ("CVSSv2 score" set to 7.2. "CVSSv2 vector" set to "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")
  • CVSSv2 severity (based on CVE-2021-4034, severity increased from "Medium" to "High")
  • Exploit attributes ("Exploit available" set to "True". "Exploit framework canvas" set to "True". "Exploit framework core" set to "True". "Exploitability ease" changed from "No known exploits are available" to "Exploits are available". "Exploit framework metasploit" set to "True". "Exploited by malware" set to "True")

Plugin Feed: 202311171511

Version 1.5

Nov 17, 2023, 12:59 PM

  • CVSS metrics ("CVSSv2 score" set to 7.2)
  • CVSS metrics ("CVSSv2 vector" set to "CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C")
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")
  • CVSSv2 severity (based on CVE-2021-4034, severity increased from "Medium" to "High")
  • Exploit attributes ("Exploit available" set to "True")
  • Exploit attributes ("Exploit framework canvas" set to "True")
  • Exploit attributes ("Exploit framework core" set to "True")
  • Exploit attributes ("Exploit framework metasploit" set to "True")
  • Exploit attributes ("Exploitability ease" changed from "No known exploits are available" to "Exploits are available")
  • Exploit attributes ("Exploited by malware" set to "True")

Plugin Feed: 202311171259

* Changelogs are generally available for changes made after Nov 1, 2022