vendor:
Deepin Linux
by:
bcoles
7.2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Deepin Linux
Affected Version From: Deepin Linux 15.5
Affected Version To: Deepin Linux 15.5
Patch Exists: NO
Related CWE: N/A
CPE: o:deepin:deepin_linux:15.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
Deepin Linux 15.5 lastore-daemon D-Bus Local Root Exploit
The lastore-daemon D-Bus configuration on Deepin Linux 15.5 permits any user in the sudo group to install arbitrary packages without providing a password, resulting in code execution as root. By default, the first user created on the system is a member of the sudo group.
Mitigation:
Restrict access to the lastore-daemon D-Bus configuration.