PT-2018-3685 · Packagekit+4 · Packagekit+4
Matthias Gerstner
·
Publicado
2018-04-23
·
Atualizado
2024-06-15
·
CVE-2018-1106
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PackageKit versions prior to 1.1.10
Description
The issue is related to insufficient authentication in PackageKit, allowing a local attacker to bypass authentication and install signed packages without administrator privileges. This can be exploited to install vulnerable packages, potentially leading to further system compromise.
Recommendations
For versions prior to 1.1.10, update to version 1.1.10 or later to resolve the issue. As a temporary workaround, consider restricting package installation privileges to prevent unauthorized package installs until the update is applied.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Packagekit
Red Hat
Suse
Ubuntu