2.1
CVSSv2

CVE-2015-3218

Published: 26/10/2015 Updated: 18/07/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) prior to 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.

Vulnerable Product Search on Vulmon Subscribe to Product

polkit project polkit

Vendor Advisories

Several security issues were fixed in PolicyKit ...
Debian Bug report logs - #796134 CVE-2015-3255 CVE-2015-4625 Package: policykit-1; Maintainer for policykit-1 is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for policykit-1 is src:policykit-1 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 19 Aug ...
Debian Bug report logs - #787932 policykit-1: CVE-2015-3218: crash authentication_agent_new with invalid object path in RegisterAuthenticationAgent Package: src:policykit-1; Maintainer for src:policykit-1 is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@ ...