A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
2018-07-10T19:29:00.290
2024-11-21T03:59:12.913
Modified
CVSSv3.1: 4.4 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Application | polkit_project | polkit | < 0.115 | Yes |