Should I worry if 'pkexec' is in a cPanel user's /home/virtfs (CVE-2021-4034)?
1
vote
1
answer
116
views
The recent security bug CVE-2021-4034 in Linux involves
/usr/bin/pkexec
. Following media reports (zdnet, etc.) I changed its permission, but also found this file:
/home/virtfs/foo/usr/bin/pkexec
for cPanel user foo
.
I don't know why a user would have pkexec
shadowed.
Unfortunately we are running an outdated WHM/cPanel (with root) on outdated CentOS 6, until we can migrate the last sites off it.
Asked by kitchin
(131 rep)
Jan 26, 2022, 06:38 AM
Last activity: Feb 1, 2022, 08:02 AM
Last activity: Feb 1, 2022, 08:02 AM