ALAS2-2020-1437

Related Vulnerabilities: CVE-2018-1116  

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure. (CVE-2018-1116)

ALAS2-2020-1437


Amazon Linux 2 Security Advisory: ALAS-2020-1437
Advisory Release Date: 2020-06-16 18:05 Pacific
Advisory Updated Date: 2020-06-17 23:40 Pacific
Severity: Low
References: CVE-2018-1116 

Issue Overview:

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure. (CVE-2018-1116)


Affected Packages:

polkit


Issue Correction:
Run yum update polkit to update your system.

New Packages:
aarch64:
    polkit-0.112-26.amzn2.aarch64
    polkit-devel-0.112-26.amzn2.aarch64
    polkit-debuginfo-0.112-26.amzn2.aarch64

i686:
    polkit-0.112-26.amzn2.i686
    polkit-devel-0.112-26.amzn2.i686
    polkit-debuginfo-0.112-26.amzn2.i686

noarch:
    polkit-docs-0.112-26.amzn2.noarch

src:
    polkit-0.112-26.amzn2.src

x86_64:
    polkit-0.112-26.amzn2.x86_64
    polkit-devel-0.112-26.amzn2.x86_64
    polkit-debuginfo-0.112-26.amzn2.x86_64