Improper authorization in PolicyKit - CVE-2018-1116
Published: July 23, 2018 / Updated: July 24, 2018
PolicyKit
Detailed vulnerability description
The vulnerability allows a local attacker to obtain potentially sensitive information or cause DoS condition on the target system.
The vulnerability exists due to improper implementation of the polkit_backend_interactive_authority_check_authorization function in the polkitd daemon. A local attacker can test for authentication and trigger authentication of unrelated processes owned by other users to access sensitive information or cause the service to crash.