Executive brief
Pardus Software Center, a tool used for managing and installing applications on the Pardus operating system, contains a security flaw in how it handles system permissions. An attacker could exploit this vulnerability to take control of high-privilege system processes. This could lead to unauthorized software installation, full system compromise, or the theft of sensitive data.
Technical details
A vulnerability involving Improper Privilege Management (CWE-269), Improper Access Control (CWE-284), and Incorrect Privilege Assignment (CWE-266) exists in the Pardus Software Center. The flaw allows an attacker to hijack a privileged process, potentially leading to local privilege escalation or unauthorized execution of administrative tasks. While the attack vector is listed as network-based, it requires user interaction (UI:R), suggesting the exploit may be triggered via malicious files or web-based delivery that interacts with the software center's handling of permissions. The issue is fixed in version 1.0.3.
Affected products
- TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center 1.0.2 to 1.0.3
Timeline
- 2026-04-29: disclosed
- 2026-04-29: advisory
- 2026-06-06: other: Last modified date