SB2015070815 - Input validation error in polkit (Alpine package)
Published: July 8, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2015-4625)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=ec563f54fcb69061dbbeb7ac0d4bc08455148f90
- https://git.alpinelinux.org/aports/commit/?id=0b52876162f2412968ff130fbb6ab254a1afad01
- https://git.alpinelinux.org/aports/commit/?id=9f939bc197b3bb38267a81e41732fe53a2373f5c
- https://git.alpinelinux.org/aports/commit/?id=a0b66a149533ede4da0e12447d96958233dbec8e
- https://git.alpinelinux.org/aports/commit/?id=5ae83ccf3e1cc61b24f9e5f130462386aaf840cb
- https://git.alpinelinux.org/aports/commit/?id=6fe5385eb32b42ebe7440f307380873153658bc0
- https://git.alpinelinux.org/aports/commit/?id=a215f1937c91916b1b5162e49e996708eb456e67
- https://git.alpinelinux.org/aports/commit/?id=39904e42477722d27b1a55bfe61a438f398e5bd2
- https://git.alpinelinux.org/aports/commit/?id=f28f43cbfd353ffd2f447445520f0a289570ded5