[Bug 1226598] New: AUDIT-FIND: logiops: unrestricted D-Bus service allows for privilege escalation with user interaction required
https://bugzilla.suse.com/show_bug.cgi?id=1226598 Bug ID: 1226598 Summary: AUDIT-FIND: logiops: unrestricted D-Bus service allows for privilege escalation with user interaction required Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: wolfgang.frisch@suse.com QA Contact: qa-bugs@suse.de Target Milestone: --- Found By: --- Blocker: --- logiops [0][1], in its default configuration, allows any unprivileged user to configure its `logid` daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This could potentially enable privilege escalation with minimal user interaction required. The most basic proof-of-concept assigns a shell command to all buttons for connected peripherals. A more crafty attacker could tailor this operation to specific software used on the system, possibly monitoring the process list and mapping malicious macros at exactly the right moment. [0] https://github.com/PixlOne/logiops [1] https://bugzilla.suse.com/show_bug.cgi?id=1225543#c3 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226598 https://bugzilla.suse.com/show_bug.cgi?id=1226598#c5 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Group|SUSE Security Internal | --- Comment #5 from Wolfgang Frisch <wolfgang.frisch@suse.com> --- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:H/SI:H/SA:H -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1226598 https://bugzilla.suse.com/show_bug.cgi?id=1226598#c6 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Comment #4 is|1 |0 private| | Status|IN_PROGRESS |RESOLVED Resolution|--- |NORESPONSE --- Comment #6 from Wolfgang Frisch <wolfgang.frisch@suse.com> --- Published -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com