Wind River Support Network

HomeDefectsLIN9-7990
Fixed

LIN9-7990 : Security Advisory - polkit - CVE-2019-6133

Created: Jan 15, 2019    Updated: Feb 25, 2019
Resolved Date: Feb 20, 2019
Found In Version: 9.0.0.19
Fix Version: 9.0.0.20
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

In PolicyKit (aka polkit) 0.115, the start time protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.

https://nvd.nist.gov/vuln/detail/CVE-2019-6133

CVEs


Live chat
Online