PolicyKit CVE-2019-6133 Unauthorized Access Vulnerability
BID:106537
CVE-2019-6133 |Info
PolicyKit CVE-2019-6133 Unauthorized Access Vulnerability
| Bugtraq ID: | 106537 |
| Class: | Design Error |
| CVE: |
CVE-2019-6133 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2019 12:00AM |
| Updated: | Jan 11 2019 12:00AM |
| Credit: | Jann Horn <[email protected]>. |
| Vulnerable: |
freedesktop PolicyKit 0.115 |
| Not Vulnerable: | |
Discussion
PolicyKit CVE-2019-6133 Unauthorized Access Vulnerability
PolicyKit is prone to an unauthorized-access vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
PolicyKit version 0.115 is vulnerable.
PolicyKit is prone to an unauthorized-access vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
PolicyKit version 0.115 is vulnerable.
References
PolicyKit CVE-2019-6133 Unauthorized Access Vulnerability
References:
References:
- backend: Compare PolkitUnixProcess uids for temporary authorizations (GitLab)
- Freedesktop Home Page (Freedesktop)
- Git Commit (Linux Kernel)
- Merge branch 'uid-compare' into 'master' (GitLab)
- Polkit GitLab Repository (GitLab)
- Polkit Product Page (Freedesktop)
- Polkit Software Releases (Freedesktop)
- polkit: temporary auth hijacking via PID reuse and non-atomic fork (Chromium)