Beveiligingsadvies
CVE-2022-23220
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.