screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
canonical screen-resolution-extra 0.17.2 |
||
canonical ubuntu linux 17.10 |
||
canonical ubuntu linux 16.04 |
||
canonical ubuntu linux 14.04 |