WordPress 5.7.2 is a security patch for a Critical Object Injection vulnerability in PHPMailer, the component that WordPress uses to send emails by default. Moments ago, we posted an analysis of the risk presented by this vulnerability. https://t.co/CmLBsME3SK
I were able in collaboration with @bl4sty to create a working Proof of Concept exploit for the new sudo CVE-2021-3156.
Tested just in Ubuntu 20.04.1 LTS, in other distros offsets may change. PoC available: https://t.co/kXYiNVV053
I ran into some issues with AppArmor today. I don’t understand why AppArmor is needed along side traditional permissions. It was confusing to debug because I had assumed I had a permission issue.