SB2015070813 - NULL pointer dereference in linux-firmware (Alpine package)
Published: July 8, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2015-3218)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path. <a href="http://cwe.mitre.org/data/definitions/476. A remote attacker can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=ec563f54fcb69061dbbeb7ac0d4bc08455148f90
- https://git.alpinelinux.org/aports/commit/?id=0b52876162f2412968ff130fbb6ab254a1afad01
- https://git.alpinelinux.org/aports/commit/?id=9f939bc197b3bb38267a81e41732fe53a2373f5c
- https://git.alpinelinux.org/aports/commit/?id=a0b66a149533ede4da0e12447d96958233dbec8e
- https://git.alpinelinux.org/aports/commit/?id=d2bfb22c8e8f67ad7d8d02704f35ec4d2a19f9b9
- https://git.alpinelinux.org/aports/commit/?id=5ae83ccf3e1cc61b24f9e5f130462386aaf840cb
- https://git.alpinelinux.org/aports/commit/?id=6fe5385eb32b42ebe7440f307380873153658bc0
- https://git.alpinelinux.org/aports/commit/?id=a215f1937c91916b1b5162e49e996708eb456e67
- https://git.alpinelinux.org/aports/commit/?id=39904e42477722d27b1a55bfe61a438f398e5bd2
- https://git.alpinelinux.org/aports/commit/?id=f28f43cbfd353ffd2f447445520f0a289570ded5