Vulnerability CVE-2018-19788: Information

Description

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Published: Dec. 3, 2018
Modified: Aug. 6, 2019
Error type identifier: CWE-20

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://gitlab.freedesktop.org/polkit/polkit/issues/74
  • Exploit
  • Patch
  • Third Party Advisory
https://bugs.debian.org/915332
  • Issue Tracking
  • Mailing List
  • Third Party Advisory
DSA-4350
  • Third Party Advisory
USN-3861-2
  • Third Party Advisory
USN-3861-1
  • Third Party Advisory
[debian-lts-announce] 20190128 [SECURITY] [DLA 1644-1] policykit-1 security update
  • Third Party Advisory
RHSA-2019:2046
    GLSA-201908-14
      RHSA-2019:3232
          1. Configuration 1

            cpe:2.3:a:polkit_project:polkit:0.115:*:*:*:*:*:*:*

            Configuration 2

            cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

            cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

            Configuration 3

            cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

            cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

            cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*

            cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

            cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*