Polkit authentification can be bypassed
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
language-selector (Ubuntu) |
Fix Released
|
High
|
Unassigned | ||
Maverick |
Fix Released
|
High
|
Martin Pitt | ||
Natty |
Fix Released
|
High
|
Unassigned |
Bug Description
Binary package hint: language-selector
Hello,
The actual polkit authentification in the language-selector dbus backend can be easily bypassed.
Steps to reproduce:
1) download ls-dbus-
2) from a terminal ./ls-dbus-
3) when the polkit agent ask you the password just click "cancel"
3) log you from tty1
4) exec "locale"
LANG has been changed anyway, it should don't... (a root function has been executed bypassing system policy)
Also, SetSystemDefaul
ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: language-selector (not installed)
ProcVersionSign
Uname: Linux 2.6.38-8-generic x86_64
Architecture: amd64
Date: Mon Apr 18 11:20:58 2011
InstallationMedia: Kubuntu 11.04 "Natty Narwhal" - Alpha amd64 (20110202)
ProcEnviron:
LANGUAGE=fr_FR
LANG=fr_FR.UTF-8
LC_MESSAGES=
SHELL=/bin/bash
SourcePackage: language-selector
UpgradeStatus: No upgrade log present (probably fresh install)
Changed in language-selector (Ubuntu Natty): | |
status: | New → Triaged |
Changed in language-selector (Ubuntu Maverick): | |
status: | New → Triaged |
importance: | Undecided → High |
visibility: | private → public |
This patch should fix the authorization bypass