Ubuntu Security Notice USN-1117-1
19th April, 2011
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.10
- Ubuntu 10.04 LTS
- Ubuntu 9.10
Local users could gain root access by using the pkexec tool in PolicyKit.
- policykit-1 - framework for managing administrative policies and privileges
Neel Mehta discovered that PolicyKit did not correctly verify the user
making authorization requests. A local attacker could exploit this to
trick pkexec into running applications with root privileges.
The problem can be corrected by updating your system to the following package version:
- Ubuntu 10.10:
- libpolkit-backend-1-0 0.96-2ubuntu1.1
- Ubuntu 10.04 LTS:
- libpolkit-backend-1-0 0.96-2ubuntu0.1
- Ubuntu 9.10:
- libpolkit-backend-1-0 0.94-1ubuntu1.1
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system update you need to reboot your computer to make
all the necessary changes.