"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Document Fdn.
Published: 2021-02-23T15:33:49.271890Z
Updated: 2024-09-16T22:14:42.289Z
Reserved: 2021-01-19T00:00:00
Link: CVE-2021-25630
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-23T16:15:13.253
Modified: 2024-11-21T05:55:10.840
Link: CVE-2021-25630
Redhat
No data.