Improper authorization in PolicyKit - CVE-2018-1116

 

Improper authorization in PolicyKit - CVE-2018-1116

Published: July 23, 2018 / Updated: July 24, 2018


Vulnerability identifier: #VU13987
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1116
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to obtain potentially sensitive information or cause DoS condition on the target system.

The vulnerability exists due to improper implementation of the polkit_backend_interactive_authority_check_authorization function in the polkitd daemon. A local attacker can test for authentication and trigger authentication of unrelated processes owned by other users to access sensitive information or cause the service to crash.


Affected software

PolicyKit
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Opensuse
Fedora
polkit (Red Hat package)
polkit

How to mitigate CVE-2018-1116

Update to version 0.116.

PolicyKit - update to 0.116
polkit (Red Hat package) - update to 0.112-26.el7
polkit - addressed in versions 0.113-16.fc27, 0.115-1.fc28

External References

Related Security Bulletins