PT-2018-10352 · Polkit+5 · Polkit+5
Matthias Gerstner
·
Published
2018-07-10
·
Updated
2024-06-15
·
CVE-2018-1116
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
polkit versions prior to 0.116
Description
A flaw in the implementation of the
polkit backend interactive authority check authorization function in polkitd allows testing for authentication and triggering authentication of unrelated processes owned by other users. This may result in a local denial of service and information disclosure.Recommendations
For versions prior to 0.116, update to version 0.116 or later to resolve the issue. As a temporary workaround, consider restricting access to the
polkit backend interactive authority check authorization function to minimize the risk of exploitation.Fix
DoS
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Polkit