Wind River Support Network

HomeDefectsLIN10-5320
Fixed

LIN10-5320 : Security Advisory - polkit - CVE-2019-6133

Created: Jan 15, 2019    Updated: Mar 6, 2019
Resolved Date: Feb 14, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.14
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

In PolicyKit (aka polkit) 0.115, the start time protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.

https://nvd.nist.gov/vuln/detail/CVE-2019-6133

CVEs


Live chat
Online