[Bug 1202933] VUL-0: CVE-2022-3560: pesign: pesign-authorize ExecStartPost script allows privilege escalation from pesign to root
https://bugzilla.suse.com/show_bug.cgi?id=1202933 https://bugzilla.suse.com/show_bug.cgi?id=1202933#c19 Gary Ching-Pang Lin <glin@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Flags|needinfo?(glin@suse.com) | --- Comment #19 from Gary Ching-Pang Lin <glin@suse.com> --- (In reply to Matthias Gerstner from comment #18)
(In reply to Matthias Gerstner from comment #1)
c) we need to fix the broken systemd hardening in Tumbleweed d) we need to fix the broken paths in SLE-15
c) and d) should only be done after the fixes are applied, lest we actually introduce the vulnerability in 2).
Thanks for handling the fix!
Do you also take care of these issues?
Sure. It's a part of my plan. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com