Back

MEDIUM

polkit: Members of 'wheel' group allowed to become root without providing a password

Published Oct 1, 2012

Description

PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentication.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the version of polkit as shipped with Red Hat Enterprise Linux 6 as it did not include the upstream commit 763faf434b445c20ae9529100d3ef5290976d0c9 that introduced this issue.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 1, 2012
Updated Aug 7, 2024
Reserved Dec 23, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Dec 9, 2011