ÍâÑóÄþ¾²Ñо¿ÍŶÓÅû¶
ȨÏÞÌáÉý
½üÈÕ£¬ÍâÑóÄþ¾²Ñо¿ÍŶÓÅû¶ÁËPolkit pkexecȨÏÞÌáÉý©¶´£¨CVE-2021-4034£©¡£¾ßÓеÍȨÏ޵Ĺ¥»÷Õß¿ÉÒÔÀûÓôË©¶´Èƹýpkexec×Ô´øµÄÄþ¾²±£»¤²½·¥£¬»ñÈ¡Ä¿±ê»úеµÄROOTȨÏÞ¡£
CVSSÆÀ·Ö£º
CVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2021-4034 | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 7.8 | E:H/RL:O/RC:C | 7.5 |
ÊÜÓ°Ïì²úÆ·£º
²úÆ·Ãû³Æ | ÊÜÓ°Ïì²úÆ·°æ±¾ | ²¹¶¡°ü/Éý¼¶°ü |
AS13000 | <= 3.7.50.19 | AS13000-polkit-cve-2021-4034-patch |
ICOS | ICOS <= 5.8.2 | polkit-update-20220128 |
ICS | ICS <= 6.0.1 | InCloudSphere-V6R05B016-b1-x86_64-S001 |
¸Ã©¶´ÊÇÓÉÓÚpkexec ÎÞ·¨ÕýÈ·´¦ÀíŲÓòÎÊý£¬´Ó¶ø½«Çé¿ö±äÁ¿×÷ΪÃüÁîÖ´ÐУ¬¾ßÓÐÈÎÒâÓû§È¨Ï޵Ĺ¥»÷Õ߶¼¿ÉÒÔÔÚĬÈÏÅäÖÃÏÂͨ¹ýÐÞ¸ÄÇé¿ö±äÁ¿À´ÀûÓôË©¶´£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄroot ȨÏÞ¡£
©¶´½â¾ö¼Æ»®£ºÇëÓû§Ö±½ÓÁªÏµ¿Í»§Ð§ÀÍÈËÔ±£¬»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄ¼¼ÊõÖ§³Ö¡£
FAQ£ºÎÞ
¸üмͼ£º20220128-V1.0-Initial Release
20220207-V1.1-Update Ôö¼ÓÊÜÓ°Ïì²úÆ·
20220215-V1.2-Update Ôö¼ÓÊÜÓ°Ïì²úÆ·
20220228-V1.3-Update Ôö¼ÓÊÜÓ°Ïì²úÆ·
»ñÈ¡¼¼ÊõÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html
±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´ÔÑù"Ìṩ£¬²»ÔÊÐíÈκÎÃ÷ʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇé¿öÏ£¬pgµç×Ó¹ÙÍø»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧµ£ÂôÁ¦ÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬Å¼È»£¬Ò»¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£pgµç×Ó¹ÙÍø±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÀû¡£