[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

PolicyKit - (bulletinapr2019)

ID: oval:org.secpod.oval:def:2104543Date: (C)2019-12-31   (M)2023-07-28
Class: PATCHFamily: unix




Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

Platform:
Sun Solaris 11
Product:
system/library/polkit
library/desktop/webkitgtk4
Reference:
bulletinapr2019
CVE-2013-4288
CVE-2018-1116
CVE    2
CVE-2013-4288
CVE-2018-1116
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies