-
-
Notifications
You must be signed in to change notification settings - Fork 3.3k
Open
Description
On ubuntu (and probably other distros), linpeas will give a false positive for CVE-2021-3560 with patched versions of libpolkit.
This is because it only checks for libpolkit 0.105-26, ignoring patch information. This is an issue on ubuntu, since it was patched in 0.105-26ubuntu1.1, but the patch number is ignored.
I'm not sure if this could be fixed universally, but it could be fixed for ubuntu by changing the grep -q 'polkit.*0\.105-26' to grep 'polkit.*0\.105-26' | grep -qv ubuntu1.[1-9].
laviRZ
Metadata
Metadata
Assignees
Labels
No labels