Qualys Security AdvisoryLooney Tunables: Local Privilege Escalation in the glibc's ld.so(CVE-2023-4911)========================================================================Contents========================================================================SummaryAnalysisProof of conceptExploitationAcknowledgmentsTimeline========================================================================Summary========================================================================The GNU C Library's dynamic loader "find[s] and load[s] the sharedobjects (shared libraries) needed by a program, prepare[s] the programto run, and then run[s] it" (man ld.so). The dynamic loader is extremelysecurity sensitive, because its code runs with elevated privileges whena local user
Qualys Security AdvisoryCVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent========================================================================Contents========================================================================SummaryBackgroundExperimentsResultsDiscussionAcknowledgmentsTimeline========================================================================Summary========================================================================"ssh-agent is a program to hold private keys used for public keyauthentication. Through use of environment variables the agent canbe located and automatically used for authentication when logging into other machines using ssh(1). . Connections to ssh-agent may beforwarded from further remote hosts using the -A
/PRNewswire/ Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of disruptive cloud-based IT, security and compliance solutions, today announced.
Sudo Bug to Affect macOS Big Sur as it Grants Root Access to Attackers Feb 3, 2021 13:30 EST
With every new build that Apple releases, we always hear that it composes of certain security fixes and performance improvements. While vulnerabilities are not new to any software, a decade-old vulnerability has now been discovered which could allow local users to gain root access. The root access is given on Unix-based systems which include macOS Big Sur. Let s dive in to see some more details on the sudo bug that can grant access to an attacker for root access on macOS Big Sur.
Sudo Bug Could Potentially Grant Root Access to Attackers on macOS Big Sur