5

privilege escalation · Issue #4327 · rustdesk/rustdesk · GitHub

 1 year ago
source link: https://github.com/rustdesk/rustdesk/issues/4327
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Contributor

Bug Description

changing settings without privileges.
(linux desktop)

How to Reproduce

  1. service started as root
  2. run rustdesk from anywhere other than /usr
    bingo we change the service settings without any rights!.

Expected Behavior

The application client should never be able to change server settings!

Operating system(s) on local side and remote side

linux EL8 (RL8)

RustDesk Version(s) on local side and remote side

1.2.0+ local: nightly as of today

Screenshots

Additional Context

#4273


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK