4.6
CVSSv2

CVE-2015-4625

Published: 26/10/2015 Updated: 30/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) prior to 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 21

opensuse opensuse 13.2

fedoraproject fedora 22

opensuse opensuse 13.1

polkit project polkit

Vendor Advisories

Debian Bug report logs - #796134 CVE-2015-3255 CVE-2015-4625 Package: policykit-1; Maintainer for policykit-1 is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for policykit-1 is src:policykit-1 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 19 Aug ...
Several security issues were fixed in PolicyKit ...