Hacker News new | ask | show | jobs
by CGamesPlay 622 days ago
The CVE has a typo; the actual is CVE-2021-4034. https://nvd.nist.gov/vuln/detail/CVE-2021-4034
2 comments

Thank you for that. I was wondering why a medium vuln was causing so much headache in a binary that wasn't even described by the article.
From the link:

>The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands.

Oh, for fucks sake.