CVE Vulnerabilities

CVE-2010-4664

Improper Privilege Management

Published: Nov 13, 2019 | Modified: Nov 18, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 MODERATE
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Consolekit Consolekit_project * 0.4.2 (excluding)
Consolekit Ubuntu artful *
Consolekit Ubuntu esm-apps/xenial *
Consolekit Ubuntu esm-infra-legacy/trusty *
Consolekit Ubuntu hardy *
Consolekit Ubuntu lucid *
Consolekit Ubuntu maverick *
Consolekit Ubuntu natty *
Consolekit Ubuntu oneiric *
Consolekit Ubuntu precise *
Consolekit Ubuntu precise/esm *
Consolekit Ubuntu quantal *
Consolekit Ubuntu raring *
Consolekit Ubuntu saucy *
Consolekit Ubuntu trusty *
Consolekit Ubuntu trusty/esm *
Consolekit Ubuntu utopic *
Consolekit Ubuntu vivid *
Consolekit Ubuntu vivid/stable-phone-overlay *
Consolekit Ubuntu vivid/ubuntu-core *
Consolekit Ubuntu wily *
Consolekit Ubuntu xenial *
Consolekit Ubuntu yakkety *
Consolekit Ubuntu zesty *

Potential Mitigations

References