Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19788

Опубликовано: 03 дек. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Средний

Описание

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:polkit_project:polkit:0.115:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.59639
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

CVSS3: 7
redhat
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

CVSS3: 8.8
debian
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user wi ...

suse-cvrf
почти 7 лет назад

Security update for polkit

suse-cvrf
около 7 лет назад

Security update for polkit

EPSS

Процентиль: 98%
0.59639
Средний

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-20