*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Seth Arnold (seth-arnold):

Hi :-)

I have (maybe) found a privilege escalation in gparted (GParted 1.3.1)

A user with unprivileged rights was granted with standard polkit rules access 
to gparted.
Once the user correctly authenticates the gparted gui loads, and the user can 
partition any attached device (that is ok!)

BUT once done, the user is presented with the summary AND there one has the 
option to 
----> SAVE DETAILS <---- (gparted-2-issue.png)

That is a BIG problem! 
One can overwrite virtually any file on the system (being root) with the 
gparted output!

Could you advise me on this matter?

Thank you very much!
Kind regards
Otto

** Affects: gparted (Ubuntu)
     Importance: Undecided
         Status: Invalid

-- 
privilege escallation
https://bugs.launchpad.net/bugs/1986913
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to