Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1116

Опубликовано: 10 июл. 2018
Источник: debian

Описание

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
policykit-1fixed0.105-21package
policykit-1no-dsastretchpackage

Примечания

  • https://cgit.freedesktop.org/polkit/commit/?id=bc7ffad53643a9c80231fc41f5582d6a8931c32c

  • https://lists.freedesktop.org/archives/polkit-devel/2018-July/000583.html

  • https://bugzilla.suse.com/show_bug.cgi?id=1099031

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 7 лет назад

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

CVSS3: 4.4
redhat
больше 7 лет назад

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

CVSS3: 4.4
nvd
больше 7 лет назад

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

suse-cvrf
больше 7 лет назад

Security update for polkit

suse-cvrf
больше 7 лет назад

Security update for polkit