Wind River Support Network

HomeDefectsLIN1018-3395
Fixed

LIN1018-3395 : Security Advisory - polkit - CVE-2019-6133

Created: Jan 15, 2019    Updated: Feb 19, 2019
Resolved Date: Jan 28, 2019
Found In Version: unknown
Fix Version: 10.18.44.4
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

In PolicyKit (aka polkit) 0.115, the start time protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.

https://nvd.nist.gov/vuln/detail/CVE-2019-6133

CVEs


Live chat
Online