Vulnerability Details CVE-2018-1116
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 14.7%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 3.6
Products affected by CVE-2018-1116
-
cpe:2.3:a:polkit_project:polkit:-
-
cpe:2.3:a:polkit_project:polkit:0.100
-
cpe:2.3:a:polkit_project:polkit:0.101
-
cpe:2.3:a:polkit_project:polkit:0.102
-
cpe:2.3:a:polkit_project:polkit:0.103
-
cpe:2.3:a:polkit_project:polkit:0.104
-
cpe:2.3:a:polkit_project:polkit:0.105
-
cpe:2.3:a:polkit_project:polkit:0.106
-
cpe:2.3:a:polkit_project:polkit:0.107
-
cpe:2.3:a:polkit_project:polkit:0.108
-
cpe:2.3:a:polkit_project:polkit:0.109
-
cpe:2.3:a:polkit_project:polkit:0.110
-
cpe:2.3:a:polkit_project:polkit:0.111
-
cpe:2.3:a:polkit_project:polkit:0.112
-
cpe:2.3:a:polkit_project:polkit:0.112.1
-
cpe:2.3:a:polkit_project:polkit:0.113
-
cpe:2.3:a:polkit_project:polkit:0.114
-
cpe:2.3:a:polkit_project:polkit:0.3
-
cpe:2.3:a:polkit_project:polkit:0.4
-
cpe:2.3:a:polkit_project:polkit:0.5
-
cpe:2.3:a:polkit_project:polkit:0.6
-
cpe:2.3:a:polkit_project:polkit:0.7
-
cpe:2.3:a:polkit_project:polkit:0.8
-
cpe:2.3:a:polkit_project:polkit:0.9
-
cpe:2.3:a:polkit_project:polkit:0.91
-
cpe:2.3:a:polkit_project:polkit:0.92
-
cpe:2.3:a:polkit_project:polkit:0.93
-
cpe:2.3:a:polkit_project:polkit:0.94
-
cpe:2.3:a:polkit_project:polkit:0.95
-
cpe:2.3:a:polkit_project:polkit:0.96
-
cpe:2.3:a:polkit_project:polkit:0.97
-
cpe:2.3:a:polkit_project:polkit:0.98
-
cpe:2.3:a:polkit_project:polkit:0.99
-
cpe:2.3:o:canonical:ubuntu_linux:12.04
-
cpe:2.3:o:debian:debian_linux:8.0