Sitemap

This vulnerability is privilege escalation in apport-cli 2.26.0, similar to CVE-2023–26604, this vulnerability only works if assign in sudoers:

Press enter or click to view image in full size

When execute less in the execution apport-cli, we can execute bash:

Press enter or click to view image in full size

Execute apport-cli with parameter file bug:

Press enter or click to view image in full size

Select any option:

Press enter or click to view image in full size
Press enter or click to view image in full size

And press key:

Press enter or click to view image in full size

And Wait, now in this point:

Press enter or click to view image in full size

In view report is where execute less:

Press enter or click to view image in full size

Now execute:

!/bin/bash

References:

Diego Condori
Diego Condori

Written by Diego Condori

eJPT | eCPPT | Pentester Red Team | Computer Science Student | Programmer