Sample Header Ad - 728x90

Should I worry if 'pkexec' is in a cPanel user's /home/virtfs (CVE-2021-4034)?

1 vote
1 answer
116 views
The recent security bug CVE-2021-4034 in Linux involves /usr/bin/pkexec. Following media reports (zdnet, etc.) I changed its permission, but also found this file: /home/virtfs/foo/usr/bin/pkexec for cPanel user foo. I don't know why a user would have pkexec shadowed. Unfortunately we are running an outdated WHM/cPanel (with root) on outdated CentOS 6, until we can migrate the last sites off it.
Asked by kitchin (131 rep)
Jan 26, 2022, 06:38 AM
Last activity: Feb 1, 2022, 08:02 AM