PT-2026-102626 · Pardus · Pardus-Parental-Control
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pardus Parental Control versions prior to 0.7.0
Description
An incorrect authorization issue exists in the polkit policy. This allows unprivileged local users to disable parental controls with root privileges. An attacker can execute the
PPCActivator.py script using the pkexec command with the --disable argument to remove all restrictions, such as application limits and DNS filtering, without requiring authentication.Recommendations
Update Pardus Parental Control to version 0.7.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pardus-Parental-Control