Description
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12526 | "loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges. |
References
History
No history.
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2024-09-16T22:14:42.289Z
Reserved: 2021-01-19T00:00:00.000Z
Link: CVE-2021-25630
No data.
Status : Modified
Published: 2021-02-23T16:15:13.253
Modified: 2024-11-21T05:55:10.840
Link: CVE-2021-25630
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD