4.4
CVSSv2

CVE-2018-8885

Published: 28/03/2018 Updated: 27/04/2018
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical screen-resolution-extra 0.17.2

canonical ubuntu linux 17.10

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

Vendor Advisories

Screen Resolution Extra could be tricked into bypassing PolicyKit authorizations ...