PT-2018-10352 · Polkit+5 · Polkit+5
Matthias Gerstner
·
Publicado
2018-07-10
·
Atualizado
2024-06-15
·
CVE-2018-1116
CVSS v3.1
4.7
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
polkit versions prior to 0.116
Description
A flaw in the implementation of the
polkit backend interactive authority check authorization function in polkitd allows testing for authentication and triggering authentication of unrelated processes owned by other users. This may result in a local denial of service and information disclosure.Recommendations
For versions prior to 0.116, update to version 0.116 or later to resolve the issue. As a temporary workaround, consider restricting access to the
polkit backend interactive authority check authorization function to minimize the risk of exploitation.Correção
DoS
Improper Authorization
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Polkit