4.6
CVSSv2

CVE-2015-3255

Published: 26/10/2015 Updated: 28/07/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) prior to 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.

Vulnerable Product Search on Vulmon Subscribe to Product

polkit project polkit

Vendor Advisories

Debian Bug report logs - #796134 CVE-2015-3255 CVE-2015-4625 Package: policykit-1; Maintainer for policykit-1 is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for policykit-1 is src:policykit-1 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 19 Aug ...
Several security issues were fixed in PolicyKit ...
Several security issues were fixed in PolicyKit ...
The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpoolc in PolicyKit (aka polkit) before 0113 might allow local users to gain privileges via duplicate action IDs in action descriptions ...