CVE-2018-1116
polkit: Improper authorization in polkit_backend_interactive_authority_check_authorization function in polkitd
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
Se ha descubierto un problema en versiones anteriores a la 0.116 de polkit. La implementación de la función polkit_backend_interactive_authority_check_authorization en polkitd permite probar la autenticación y desencadenar la autenticación de procesos no relacionados propiedad de otros usuarios. Esto podría resultar en una denegación de servicio (DoS) local y una divulgación de información.
It was found that Polkit's CheckAuthorization and RegisterAuthenticationAgent D-Bus calls did not validate the client provided UID. A specially crafted program could use this flaw to submit arbitrary UIDs, triggering various denial of service or minor disclosures, such as which authentication is cached in the victim's session.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-04 CVE Reserved
- 2018-07-10 CVE Published
- 2023-07-04 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
- CWE-862: Missing Authorization
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2018/07/msg00042.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1116 | 2020-05-05 | |
https://cgit.freedesktop.org/polkit/commit/?id=bc7ffad5364 | 2020-05-05 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201908-14 | 2020-05-05 | |
https://usn.ubuntu.com/3717-2 | 2020-05-05 | |
https://access.redhat.com/security/cve/CVE-2018-1116 | 2020-03-31 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1595404 | 2020-03-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | esm |
Affected
| ||||||
Polkit Project Search vendor "Polkit Project" | Polkit Search vendor "Polkit Project" for product "Polkit" | < 0.115 Search vendor "Polkit Project" for product "Polkit" and version " < 0.115" | - |
Affected
|