4.4
CVSSv3

CVE-2018-1116

Published: 10/07/2018 Updated: 05/05/2020
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 2.5 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

canonical ubuntu linux 12.04

polkit project polkit

Vendor Advisories

Synopsis Low: polkit security and bug fix update Type/Severity Security Advisory: Low Topic An update for polkit is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, which g ...
Debian Bug report logs - #903563 polkit: CVE-2018-1116: polkitd trusting client-supplied UID allows spoofed authentication dialogs Package: policykit-1; Maintainer for policykit-1 is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for policykit-1 is src:policykit-1 (PTS, buildd, popcon) Repor ...
Several security issues were fixed in PolicyKit ...
Several security issues were fixed in PolicyKit ...
A flaw was found in polkit before version 0116 The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users This may result in a local DoS and information disclosure (CVE-2018-1116) ...
It was found that Polkit's CheckAuthorization and RegisterAuthenticationAgent D-Bus calls did not validate the client provided UID A specially crafted program could use this flaw to submit arbitrary UIDs, triggering various denial of service or minor disclosures, such as which authentication is cached in the victim's session ...