PolicyKit Grant Helper Password Handling Local Format String Vulnerability
BID:28702
Info
PolicyKit Grant Helper Password Handling Local Format String Vulnerability
| Bugtraq ID: | 28702 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1658 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 09 2008 12:00AM |
| Updated: | Apr 18 2008 12:29AM |
| Credit: | Boris Edmann |
| Vulnerable: |
Red Hat Fedora 8 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 freedesktop.org PolicyKit 0.7 freedesktop.org PolicyKit 0.6 |
| Not Vulnerable: | |
Discussion
PolicyKit Grant Helper Password Handling Local Format String Vulnerability
PolicyKit is prone to a local format-string vulnerability because it fails to adequately sanitize user-supplied input before passing it to a formatted-printing function.
Successfully exploiting this issue will allow local attackers to bypass authentication or to cause a denial of service. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
PolicyKit 0.6 is vulnerable; other versions may also be affected.
PolicyKit is prone to a local format-string vulnerability because it fails to adequately sanitize user-supplied input before passing it to a formatted-printing function.
Successfully exploiting this issue will allow local attackers to bypass authentication or to cause a denial of service. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.
PolicyKit 0.6 is vulnerable; other versions may also be affected.
Exploit / POC
PolicyKit Grant Helper Password Handling Local Format String Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PolicyKit Grant Helper Password Handling Local Format String Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
freedesktop.org PolicyKit 0.6
freedesktop.org PolicyKit 0.7
Solution:
The vendor has released fixes. Please see the references for more information.
freedesktop.org PolicyKit 0.6
-
freedesktop.org Patch for 0.6
http://bugs.freedesktop.org/attachment.cgi?id=15671
freedesktop.org PolicyKit 0.7
-
freedesktop Patch for 0.7
http://bugs.freedesktop.org/attachment.cgi?id=15591
References
PolicyKit Grant Helper Password Handling Local Format String Vulnerability
References:
References:
- Bug#: 15295 format string vulnerability in password input (freedesktop.org)
- fix for CVE-2008-1658: format string vulnerability in password input (freedesktop.org)
- policykit or policykit-gnome do not work with passwords containing % character (Launchpad)
- PolicyKit Summary Page (freedesktop.org)
- Bugzilla Bug 439982: CVE-2008-1658 PolicyKit: format string vulnerability (Red Hat)