Grinch Bug may be much worse than Shellshock, experts say
Security researchers have discovered a critical vulnerability dubbed the Grinch Bug, which can be exploited by malicious hackers to gain unauthorized root access to Linux.
The vulnerability concerns the Linux authorization system and allows privilege escalation via the wheel .
[alert variation=”alert-info”]In computer science, the term Unix wheel refers to a user account with special administrative rights, through which the SU command is controlled, which in turn allows the escalation of the rights of a simple user and their elevation to superuser.[/alert]
The new bug has left Linux system administrators on edge, just days after Poodle – another deadly bug from 2014 – resurfaced. The Grinch Bug affects all distributions of the operating system and its successful exploitation could give any attacker root access, without the use of passwords or special encryption keys.
The dangerous bug was discovered by security researchers at Alert Logic on Tuesday. The researchers say that a hacker could exploit the vulnerability either by converting registered user accounts into wheels or by successfully exploiting the Policy Kit. “Polkit” is a graphical user interface that is used by regular users to perform tasks that require administrator privileges.

