SB2016111504 - Gentoo update for polkit
Published: November 15, 2016 Updated: November 15, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2015-3255)
The vulnerability allows a local non-authenticated attacker to read and manipulate data.
The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.
Remediation
Install update from vendor's website.