*** This bug is a security vulnerability *** You have been subscribed to a public security bug by Seth Arnold (seth-arnold):
Hi :-) I have (maybe) found a privilege escalation in gparted (GParted 1.3.1) A user with unprivileged rights was granted with standard polkit rules access to gparted. Once the user correctly authenticates the gparted gui loads, and the user can partition any attached device (that is ok!) BUT once done, the user is presented with the summary AND there one has the option to ----> SAVE DETAILS <---- (gparted-2-issue.png) That is a BIG problem! One can overwrite virtually any file on the system (being root) with the gparted output! Could you advise me on this matter? Thank you very much! Kind regards Otto ** Affects: gparted (Ubuntu) Importance: Undecided Status: Invalid -- privilege escallation https://bugs.launchpad.net/bugs/1986913 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs