[Bug 1202933] VUL-0: CVE-2022-3560: pesign: pesign-authorize ExecStartPost script allows privilege escalation from pesign to root
https://bugzilla.suse.com/show_bug.cgi?id=1202933 https://bugzilla.suse.com/show_bug.cgi?id=1202933#c18 Matthias Gerstner <matthias.gerstner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Flags| |needinfo?(glin@suse.com) --- Comment #18 from Matthias Gerstner <matthias.gerstner@suse.com> --- (In reply to Matthias Gerstner from comment #1)
c) we need to fix the broken systemd hardening in Tumbleweed d) we need to fix the broken paths in SLE-15
c) and d) should only be done after the fixes are applied, lest we actually introduce the vulnerability in 2).
Thanks for handling the fix! Do you also take care of these issues? -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com