安全公告详情

NS-SA-2022-0094

2022-11-09 12:33:35

简介

important: polkit/graphviz security update

严重级别

important

主题

An update for polkit/graphviz is now available for NewStart CGSL MAIN 6.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

polkit: This package provides debug information for package polkit. Debug information is useful when developing applications that use this package or when debugging this package.
graphviz: Ocaml extension for graphviz.


Security Fix(es):
polkit: A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.(CVE-2021-4034)
polkit: bugfix
graphviz: A flaw was found in graphviz. A wrong assumption in record_init function leads to an off-by-one write in parse_reclbl function, allowing an attacker who can provide graph input to potentially execute code when the label of a node is invalid and shorter than two characters. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-18032)
graphviz: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.02.B0B9.

影响组件

  • polkit
  • graphviz

影响产品

  • CGSL MAIN 6.02

更新包

{"fix":[{"product":"CGSL MAIN 6.02","pkgs":[{"binary":["polkit-0.115-13.el8_5.1.x86_64.rpm","polkit-devel-0.115-13.el8_5.1.x86_64.rpm","polkit-docs-0.115-13.el8_5.1.noarch.rpm","polkit-libs-0.115-13.el8_5.1.x86_64.rpm"],"source":"polkit-0.115-13.el8_5.1.src.rpm"},{"binary":["graphviz-2.40.1-43.el8.x86_64.rpm"],"source":"graphviz-2.40.1-43.el8.src.rpm"}]}]}

CVE

参考