SB2015070814 - Permissions, Privileges, and Access Controls in polkit (Alpine package)
Published: July 8, 2015
Security Bulletin ID
SB2015070814
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-3255)
The vulnerability allows a local non-authenticated attacker to read and manipulate data.
The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=ec563f54fcb69061dbbeb7ac0d4bc08455148f90
- https://git.alpinelinux.org/aports/commit/?id=0b52876162f2412968ff130fbb6ab254a1afad01
- https://git.alpinelinux.org/aports/commit/?id=9f939bc197b3bb38267a81e41732fe53a2373f5c
- https://git.alpinelinux.org/aports/commit/?id=a0b66a149533ede4da0e12447d96958233dbec8e
- https://git.alpinelinux.org/aports/commit/?id=5ae83ccf3e1cc61b24f9e5f130462386aaf840cb
- https://git.alpinelinux.org/aports/commit/?id=6fe5385eb32b42ebe7440f307380873153658bc0
- https://git.alpinelinux.org/aports/commit/?id=a215f1937c91916b1b5162e49e996708eb456e67
- https://git.alpinelinux.org/aports/commit/?id=39904e42477722d27b1a55bfe61a438f398e5bd2
- https://git.alpinelinux.org/aports/commit/?id=f28f43cbfd353ffd2f447445520f0a289570ded5