Description
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1448-1 | policykit-1 security update |
EUVD |
EUVD-2018-11760 | A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure. |
Ubuntu USN |
USN-3717-1 | PolicyKit vulnerabilities |
Ubuntu USN |
USN-3717-2 | PolicyKit vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T03:51:48.873Z
Reserved: 2017-12-04T00:00:00.000Z
Link: CVE-2018-1116
No data.
Status : Modified
Published: 2018-07-10T19:29:00.290
Modified: 2024-11-21T03:59:12.913
Link: CVE-2018-1116
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN