A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Debian Linux Subscribe
Polkit Project Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1448-1 policykit-1 security update
EUVD EUVD EUVD-2018-11760 A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
Ubuntu USN Ubuntu USN USN-3717-1 PolicyKit vulnerabilities
Ubuntu USN Ubuntu USN USN-3717-2 PolicyKit vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T03:51:48.873Z

Reserved: 2017-12-04T00:00:00

Link: CVE-2018-1116

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-10T19:29:00.290

Modified: 2024-11-21T03:59:12.913

Link: CVE-2018-1116

cve-icon Redhat

Severity : Low

Publid Date: 2018-07-10T00:00:00Z

Links: CVE-2018-1116 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses