Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-2046

Опубликовано: 13 авг. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-2046: polkit security and bug fix update (MODERATE)

[0.112-22.0.1]

  • Increase timeout to avoid defunct processes [Orabug: 26930744]

[0.112-22]

  • pkttyagent: polkit-agent-helper-1 timeout leaves tty echo disabled
  • Resolves: rhbz#1325512

[0.112-21]

  • Mitigation of regression caused by fix of CVE-2018-19788
  • Resolves: rhbz#1656377

[0.112-20]

  • Fix of CVE-2019-6133, PID reuse via slow fork
  • Resolves: rhbz#1667312

[0.112-19]

  • Fix of CVE-2018-19788, priv escalation with high UIDs
  • Resolves: rhbz#1656377

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

polkit

0.112-22.0.1.el7

polkit-devel

0.112-22.0.1.el7

polkit-docs

0.112-22.0.1.el7

Oracle Linux x86_64

polkit

0.112-22.0.1.el7

polkit-devel

0.112-22.0.1.el7

polkit-docs

0.112-22.0.1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

CVSS3: 7
redhat
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

CVSS3: 8.8
nvd
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

CVSS3: 8.8
debian
около 7 лет назад

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user wi ...

suse-cvrf
почти 7 лет назад

Security update for polkit