* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, November 28, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Flutter Entertainment (NYSE:FLUT): Assessing Value After Q3 Results, New Guidance, and Buyback Completion – Yahoo Finance

    Flutter Entertainment (NYSE:FLUT): Assessing Value After Q3 Results, New Guidance, and Buyback Completion – Yahoo Finance

    K&C Sports & Entertainment Law Weekly Roundup – November 2025 #4 – JD Supra

    K&C Sports & Entertainment Law Weekly Roundup – November 2025 #4 – JD Supra

    Titans Entertainment | Week 12 vs Seahawks – Tennessee Titans

    Titans Take on Seahawks: Week 12 Showdown

    Beloved country music duo ending show after nearly 50 years – PennLive.com

    Beloved country music duo ending show after nearly 50 years – PennLive.com

    Macy’s Thanksgiving Day parade 2025 route: Everything to know before you go or livestream the event – NJ.com

    Macy’s Thanksgiving Day Parade 2025: The Ultimate Guide to the Route and Live Viewing

    ‘General Hospital’ Alums Greg Vaughan & Natalia Livingston Have Surprise Reunion – themercury.com

    General Hospital’ Stars Greg Vaughan & Natalia Livingston Reunite in Surprise Encounter!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Hang Feng (NASDAQ: FOFO) secures SFC upgrade for Type 4 & 9 virtual asset roles – Stock Titan

    Hang Feng (NASDAQ: FOFO) secures SFC upgrade for Type 4 & 9 virtual asset roles – Stock Titan

    How modern technology is reshaping military operations in the Indo-Pacific – Breaking Defense

    How Cutting-Edge Technology is Transforming Military Operations in the Indo-Pacific

    IMD Future Readiness Indicator – Technology 2025 – imd.org

    IMD Future Readiness Indicator – Technology 2025 – imd.org

    CBF to revolutionise officiating with Genius Sports’ semi-automated offside technology in 2026 – Genius Sports

    CBF Set to Transform Officiating with Game-Changing Semi-Automated Offside Technology in 2026

    Columbia Global Technology Growth Fund Celebrates 25-Year Anniversary – The AI Journal

    Columbia Global Technology Growth Fund Celebrates 25-Year Anniversary – The AI Journal

    New institute to accelerate adoption of breakthrough medical technologies – Northwestern Now News

    Revolutionary New Institute Poised to Accelerate Breakthrough Medical Technologies

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Flutter Entertainment (NYSE:FLUT): Assessing Value After Q3 Results, New Guidance, and Buyback Completion – Yahoo Finance

    Flutter Entertainment (NYSE:FLUT): Assessing Value After Q3 Results, New Guidance, and Buyback Completion – Yahoo Finance

    K&C Sports & Entertainment Law Weekly Roundup – November 2025 #4 – JD Supra

    K&C Sports & Entertainment Law Weekly Roundup – November 2025 #4 – JD Supra

    Titans Entertainment | Week 12 vs Seahawks – Tennessee Titans

    Titans Take on Seahawks: Week 12 Showdown

    Beloved country music duo ending show after nearly 50 years – PennLive.com

    Beloved country music duo ending show after nearly 50 years – PennLive.com

    Macy’s Thanksgiving Day parade 2025 route: Everything to know before you go or livestream the event – NJ.com

    Macy’s Thanksgiving Day Parade 2025: The Ultimate Guide to the Route and Live Viewing

    ‘General Hospital’ Alums Greg Vaughan & Natalia Livingston Have Surprise Reunion – themercury.com

    General Hospital’ Stars Greg Vaughan & Natalia Livingston Reunite in Surprise Encounter!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Hang Feng (NASDAQ: FOFO) secures SFC upgrade for Type 4 & 9 virtual asset roles – Stock Titan

    Hang Feng (NASDAQ: FOFO) secures SFC upgrade for Type 4 & 9 virtual asset roles – Stock Titan

    How modern technology is reshaping military operations in the Indo-Pacific – Breaking Defense

    How Cutting-Edge Technology is Transforming Military Operations in the Indo-Pacific

    IMD Future Readiness Indicator – Technology 2025 – imd.org

    IMD Future Readiness Indicator – Technology 2025 – imd.org

    CBF to revolutionise officiating with Genius Sports’ semi-automated offside technology in 2026 – Genius Sports

    CBF Set to Transform Officiating with Game-Changing Semi-Automated Offside Technology in 2026

    Columbia Global Technology Growth Fund Celebrates 25-Year Anniversary – The AI Journal

    Columbia Global Technology Growth Fund Celebrates 25-Year Anniversary – The AI Journal

    New institute to accelerate adoption of breakthrough medical technologies – Northwestern Now News

    Revolutionary New Institute Poised to Accelerate Breakthrough Medical Technologies

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Alarm raised over Mozilla VPN: Wonky authorization check lets users cause havoc

August 5, 2023
in Technology
Alarm raised over Mozilla VPN: Wonky authorization check lets users cause havoc
Share on FacebookShare on Twitter

A security engineer at Linux distro maker SUSE has published an advisory for a flaw in the Mozilla VPN client for Linux that has yet to be addressed in a publicly released fix because the disclosure process went off the rails.

In a post to the Openwall security mailing list, Matthias Gerstner describes a broken authentication check in Mozilla VPN client v2.14.1, released on May 30.

Essentially, the client can be exploited by any user on a system to, among other things, configure their own arbitrary VPN setup, redirect network traffic to outside parties, and break existing VPN setups. That’s no good on shared computers with multiple users.

The issue was identified, says Gerstner, when an openSUSE community manager wanted to add the Mozilla VPN client to openSUSE Tumbleweed, a Linux distribution. The software was reviewed by the SUSE security team, a standard procedure, and they found the VPN software “contains a privileged D-Bus service running as root and a Polkit policy.”

Polkit, formerly PolicyKit, is an authorization API for privileged programs. The SUSE security team noticed that the privileged mozillavpn linuxdaemon process had incorrect authorization logic.

Citing the listed XML-based Polkit policy declarations, Gerstner observed that the way the authentication check is written, the code asks Polkit to determine whether the privileged Mozilla VPN D-Bus service – rather than the user – is authorized to perform the action.

Since the D-Bus service runs with root privileges, the authorization check always returns true. That means the D-Bus call will work for any user account, regardless of privileges.

Mozilla ups its VPN game – and the price – with split tunneling for Android, iOS

Mozilla so sorry for intrusive Firefox VPN popup ad

Mozilla VPN now nudges users to put shields up on dodgy networks, adds LAN access

Mozilla unveils $4.99/month subscription-based VPN, says it won’t hang onto user logs

“The impact is that arbitrary local users can configure arbitrary VPN setups using Mozilla VPN and thus possibly redirect network traffic to malicious parties, pretend that a secure VPN is present while it actually isn’t, perform a denial-of-service against an existing VPN connection or other integrity violations,” said Gerstner.

Gerstner also calls out the absence of any Polkit authorization checks for various other D-Bus methods like getLogs(), cleanupLogs(), runningApps(), firewallApp(), firewallClear(), and deactivate(). These all execute functions that should be authorized. For example, it’s fundamentally insecure to let any local account on a system deactivate another user’s VPN.

Responsible disclosure needs to work both ways

Polkit itself had a recent significant security issue, but the Mozilla VPN vulnerability is the result of improper implementation. What makes it noteworthy is the way the disclosure was handled.

According to Gerstner, the issue was privately disclosed to Mozilla on May 4, and SUSE heard nothing further until June 12, when its security team learned the flaw had been disclosed in a GitHub pull request to the Mozilla VPN repo.

“We asked upstream once more what their intentions are regarding coordinated disclosure but did not get a proper response,” said Gerstner.

Nonetheless, the SUSE team waited until Thursday, August 3, after 90 days had elapsed, to post publicly about the flaw, which Mozilla has now assigned CVE-2023-4104.

Gerstner says Mozilla VPN plans to stop using Polkit authentication completely in the upcoming v2.16.0 release, which does nothing to change the fact that all the D-Bus APIs remain unauthenticated and usable by any local user.

Improved authorization is expected in v2.17.0 – which does not yet have a release date – by requiring the D-Bus caller to have the CAP_NET_ADMIN permission, or the UID associated with the user who activated the connection. This is expected in one or two months.

As for the other potential information leaks described in the post, Gerstner says there is no word on how or when those will be addressed.

Asked to comment, a Mozilla spokesperson told The Register that “while the timing is uncertain,” the organization anticipates sharing more information on Monday. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/08/04/mozilla_vpn_linux_flaw/

Tags: Alarmraisedtechnology
Previous Post

Twitch Star’s NYC Event Devolves Into Chaos, Transforming Union Square Into Thunderdome

Next Post

Behold, Incus: Check out this fork of Canonical’s LXD ‘containervisor’

Argentino Lake: the glacial giant shaping Patagonian ecology and attracting sustainable tourism in Santa Cruz – Noticias Ambientales

Argentino Lake: The Glacial Giant Revolutionizing Patagonia’s Ecology and Sparking Sustainable Tourism in Santa Cruz

November 28, 2025
Fingernails And Indigestion At The 2025 Ig Nobel Prizes – Science Friday

Fingernails and Indigestion Steal the Spotlight at the 2025 Ig Nobel Prizes

November 28, 2025
Fingernails And Indigestion At The 2025 Ig Nobel Prizes | Science Friday – WNYC Studios | Podcasts

Fingernails and Indigestion Steal the Spotlight at the 2025 Ig Nobel Prizes

November 28, 2025
You know you grew up in the hippie generation if these 10 experiences defined your youth – VegOut

You know you grew up in the hippie generation if these 10 experiences defined your youth – VegOut

November 28, 2025
Hang Feng (NASDAQ: FOFO) secures SFC upgrade for Type 4 & 9 virtual asset roles – Stock Titan

Hang Feng (NASDAQ: FOFO) secures SFC upgrade for Type 4 & 9 virtual asset roles – Stock Titan

November 28, 2025
ESPN predicts the final score of Alabama football vs. Auburn – Yahoo Sports

ESPN predicts the final score of Alabama football vs. Auburn – Yahoo Sports

November 28, 2025
Pochettino: USMNT must ‘think big,’ aim to win 2026 World Cup – ESPN

Pochettino Inspires USMNT to Dream Big and Aim for Glory in the 2026 World Cup

November 28, 2025
The economy is slowing and inflation is growing. Here’s how to prepare. – Houston Chronicle

The economy is slowing and inflation is growing. Here’s how to prepare. – Houston Chronicle

November 28, 2025
Flutter Entertainment (NYSE:FLUT): Assessing Value After Q3 Results, New Guidance, and Buyback Completion – Yahoo Finance

Flutter Entertainment (NYSE:FLUT): Assessing Value After Q3 Results, New Guidance, and Buyback Completion – Yahoo Finance

November 28, 2025
How the Texans are changing the narrative about mental health and the NFL – Houston Chronicle

How the Texans Are Sparking a Powerful New Dialogue on Mental Health in the NFL

November 28, 2025

Categories

Archives

November 2025
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
« Oct    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (942)
  • Economy (961)
  • Entertainment (21,836)
  • General (18,438)
  • Health (10,001)
  • Lifestyle (972)
  • News (22,149)
  • People (966)
  • Politics (973)
  • Science (16,175)
  • Sports (21,462)
  • Technology (15,942)
  • World (948)

Recent News

Argentino Lake: the glacial giant shaping Patagonian ecology and attracting sustainable tourism in Santa Cruz – Noticias Ambientales

Argentino Lake: The Glacial Giant Revolutionizing Patagonia’s Ecology and Sparking Sustainable Tourism in Santa Cruz

November 28, 2025
Fingernails And Indigestion At The 2025 Ig Nobel Prizes – Science Friday

Fingernails and Indigestion Steal the Spotlight at the 2025 Ig Nobel Prizes

November 28, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version