ÍâÑóÇå¾²Ñо¿ÍŶÓÅû¶
ȨÏÞÌáÉý
¿ËÈÕ£¬ÍâÑóÇå¾²Ñо¿ÍŶÓÅû¶ÁËPolkit pkexecȨÏÞÌáÉýÎó²î£¨CVE-2021-4034£©¡£¾ßÓеÍȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÈƹýpkexec×Ô´øµÄÇå¾²±£»¤²½·¥£¬»ñÈ¡Ä¿µÄ»úеµÄROOTȨÏÞ¡£
CVSSÆÀ·Ö£º
CVE | V3.1 Vector(Base) | Base Score | V3.1 Vector(Temporal Score) | Temporal Score |
CVE-2021-4034 | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 7.8 | E:H/RL:O/RC:C | 7.5 |
ÊÜÓ°Ïì²úÆ·£º
²úÆ·Ãû³Æ | ÊÜÓ°Ïì²úÆ·°æ±¾ | ²¹¶¡°ü/Éý¼¶°ü |
AS13000 | <= 3.7.50.19 | AS13000-polkit-cve-2021-4034-patch |
ICOS | ICOS <= 5.8.2 | polkit-update-20220128 |
ICS | ICS <= 6.0.1 | InCloudSphere-V6R05B016-b1-x86_64-S001 |
¸ÃÎó²îÊÇÓÉÓÚpkexec ÎÞ·¨×¼È·´¦Öóͷ£Å²ÓòÎÊý£¬´Ó¶ø½«ÇéÐαäÁ¿×÷ΪÏÂÁîÖ´ÐУ¬¾ßÓÐí§ÒâÓû§È¨Ï޵Ĺ¥»÷Õ߶¼¿ÉÒÔÔÚĬÈÏÉèÖÃÏÂͨ¹ýÐÞ¸ÄÇéÐαäÁ¿À´Ê¹ÓôËÎó²î£¬´Ó¶ø»ñµÃÊÜÓ°ÏìÖ÷»úµÄroot ȨÏÞ¡£
Îó²î½â¾ö¼Æ»®£ºÇëÓû§Ö±½ÓÁªÏµ¿Í»§·þÎñÖ°Ô±£¬»ñÈ¡²¹¶¡ÒÔ¼°Ïà¹ØµÄÊÖÒÕÖ§³Ö¡£
FAQ£ºÎÞ
¸üмͼ£º20220128-V1.0-Initial Release
20220207-V1.1-Update ÔöÌíÊÜÓ°Ïì²úÆ·
20220215-V1.2-Update ÔöÌíÊÜÓ°Ïì²úÆ·
20220228-V1.3-Update ÔöÌíÊÜÓ°Ïì²úÆ·
»ñÈ¡ÊÖÒÕÖ§³Ö£º/lcjtww/2317452/2317456/2317460/index.html
±¾ÎĵµÌṩµÄËùÓÐÊý¾ÝºÍÐÅÏ¢½ö¹©²Î¿¼£¬ÇÒ"°´ÔÑù"Ìṩ£¬²»ÔÊÐíÈκÎÕÑʾ¡¢Ä¬Ê¾ºÍ·¨¶¨µÄµ£±££¬°üÀ¨(µ«²»ÏÞÓÚ)¶ÔÊÊÏúÐÔ¡¢ÊÊÓÃÐÔ¼°²»ÇÖȨµÄµ£±£¡£ÔÚÈκÎÇéÐÎÏ£¬K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾»òÆäÖ±½Ó»ò¼ä½Ó¿ØÖƵÄ×Ó¹«Ë¾£¬»òÆ乩ӦÉÌ£¬¾ù²î³ØÈκÎÒ»·½ÒòÒÀÀµ»òʹÓñ¾ÐÅÏ¢¶øÔâÊܵÄÈκÎËðʧ¼ç¸ºÔðÈΣ¬°üÀ¨Ö±½Ó£¬¼ä½Ó£¬ÎÞÒ⣬һ¶¨µÄÉÌÒµÀûÈóËðʧ»òÌØÊâËðʧ¡£K8¿·¢¡¤¹ú¼Ê¹Ù·½ÍøÕ¾±£´æËæʱ¸ü¸Ä»ò¸üдËÎĵµµÄȨÁ¦¡£