Executive brief
Pardus About is a system information utility in the Pardus Linux distribution. A missing authorization vulnerability allows users to access or modify system information that should be restricted based on user privileges, potentially exposing sensitive configuration data or enabling unauthorized system changes.
Technical details
The vulnerability is a missing authorization (broken access control) issue in the Pardus About component, which fails to properly enforce access control checks on sensitive operations. An attacker with local access can bypass privilege level restrictions to read or modify system information that should be protected. The vulnerability affects versions 1.2.1 through 1.2.4. The attack vector is local, and no authentication bypass is required beyond existing system access. Patches are available in version 1.2.5 and later.
Affected products
- TUBITAK BILGEM Pardus About 1.2.1 before 1.2.5
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Fixed in version 1.2.5