PT-2018-3685 · Packagekit+4 · Packagekit+4
Matthias Gerstner
·
Published
2018-04-23
·
Updated
2024-06-15
·
CVE-2018-1106
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PackageKit versions prior to 1.1.10
Description
The issue is related to insufficient authentication in PackageKit, allowing a local attacker to bypass authentication and install signed packages without administrator privileges. This can be exploited to install vulnerable packages, potentially leading to further system compromise.
Recommendations
For versions prior to 1.1.10, update to version 1.1.10 or later to resolve the issue. As a temporary workaround, consider restricting package installation privileges to prevent unauthorized package installs until the update is applied.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Packagekit
Red Hat
Suse
Ubuntu