ANOTHER SYSTEMD EXPLOIT

UNPRIVILEGED USERS WITH UID > INT_MAX CAN SUCCESSFULLY EXECUTE ANY SYSTEMCTL COMMAND.

github.com/systemd/systemd/issues/11026

archive.is/73vP2

Attached: poettering.jpg (1280x960, 236.53K)

Other urls found in this thread:

smcv.pseudorandom.co.uk/2015/why_polkit/
en.wikipedia.org/wiki/C18_(C_standard_revision)
twitter.com/NSFWRedditImage

it juts passes a password

Pottering:
Such a typical response.

WTF does polkit even do? It's just one of those pieces of shitware that I habitually uninstall.

It's to allow normal users to peform tasks that should normally require admin access.
smcv.pseudorandom.co.uk/2015/why_polkit/
Describes it well.

That's a good explanation, thanks.
I'm still not going to use it because I don't need such a thing, but at least I can understand why it exists.

...

What is all this gibberish? Help me with my taskbar, it's disappeared. Obviously your fault since the last time I paid you to backup my video files.

It's not an exploit per say, but it definietly goes to show how bad code quality is.

how does this ever happen