Improper authentication in PackageKit - CVE-2018-1106
Published: April 25, 2018
Vulnerability identifier: #VU12144
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1106
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to bypass security restrictions on the target system.
The weakness exists in the pk_transaction_authorize_actions_finished_cb function in the pk-transaction.c source code file due to improper authentication restrictions. A local attacker can bypass authentication and install signed packages on the system without authorization.
The weakness exists in the pk_transaction_authorize_actions_finished_cb function in the pk-transaction.c source code file due to improper authentication restrictions. A local attacker can bypass authentication and install signed packages on the system without authorization.
Affected software
PackageKit
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Fedora
PackageKit
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Fedora
PackageKit
How to mitigate CVE-2018-1106
Update to version 1.1.10.
PackageKit - addressed in versions 1.1.10-1.fc27, 1.1.10-1.fc28