PT-2018-10352 · Polkit+5 · Polkit+5

Matthias Gerstner

·

Published

2018-07-10

·

Updated

2024-06-15

·

CVE-2018-1116

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions polkit versions prior to 0.116
Description A flaw in the implementation of the polkit backend interactive authority check authorization function in polkitd allows testing for authentication and triggering authentication of unrelated processes owned by other users. This may result in a local denial of service and information disclosure.
Recommendations For versions prior to 0.116, update to version 0.116 or later to resolve the issue. As a temporary workaround, consider restricting access to the polkit backend interactive authority check authorization function to minimize the risk of exploitation.

Fix

DoS

Improper Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1997
CESA-2020_1135
CVE-2018-1116
DLA-1448-1
OPENSUSE-SU-2018_2021-1
OPENSUSE-SU-2018_2284-1
OPENSUSE-SU-2024:11180-1
RHSA-2020:1135
RHSA-2020_1135
SUSE-SU-2018:2163-1
SUSE-SU-2018:2165-1
SUSE-SU-2018_2163-1
SUSE-SU-2018_2165-1
USN-3717-1
USN-3717-2

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Polkit