MGASA-2015-0262
Dashboard / Vulnerabilities / MGASA-2015-0262
MGASA-2015-0262
Summary: Updated polkit package fixes security vulnerabilities
Details: Local privilege escalation in polkit before 0.113 due to predictable authentication session cookie values (CVE-2015-4625). Various memory corruption vulnerabilities in polkit before 0.113 in the use of the JavaScript interpreter, possibly leading to local privilege escalation (CVE-2015-3256). Memory corruption vulnerability in polkit before 0.113 in handling duplicate action IDs, possibly leading to local privilege escalation (CVE-2015-3255). Denial of service issue in polkit before 0.113 which allowed any local user to crash polkitd (CVE-2015-3218).
References: https://advisories.mageia.org/MGASA-2015-0262.html, https://bugs.mageia.org/show_bug.cgi?id=16135, http://lists.freedesktop.org/archives/polkit-devel/2015-July/000432.html
Affected packages
Package
Name: polkit
Purl: pkg:rpm/mageia/polkit?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
