CVE Vulnerabilities

CVE-2015-4625

Published: Oct 26, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
1 LOW
AV:L/AC:H/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 21 (including) 21 (including)
Fedora Fedoraproject 22 (including) 22 (including)
Opensuse Opensuse 13.1 (including) 13.1 (including)
Opensuse Opensuse 13.2 (including) 13.2 (including)
Policykit-1 Ubuntu artful *
Policykit-1 Ubuntu bionic *
Policykit-1 Ubuntu cosmic *
Policykit-1 Ubuntu devel *
Policykit-1 Ubuntu disco *
Policykit-1 Ubuntu eoan *
Policykit-1 Ubuntu focal *
Policykit-1 Ubuntu groovy *
Policykit-1 Ubuntu hirsute *
Policykit-1 Ubuntu precise *
Policykit-1 Ubuntu precise/esm *
Policykit-1 Ubuntu trusty *
Policykit-1 Ubuntu utopic *
Policykit-1 Ubuntu vivid *
Policykit-1 Ubuntu vivid/stable-phone-overlay *
Policykit-1 Ubuntu wily *
Policykit-1 Ubuntu xenial *
Policykit-1 Ubuntu yakkety *
Policykit-1 Ubuntu zesty *

References