CVE-2008-1658Use of Externally-Controlled Format String in Policykit-1

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 67.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 11
Latest updateMay 1

Description

Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in a password.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages2 packages

debiandebian/policykit-1< policykit-1 0.8-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mw7g-wfcq-49r3: Format string vulnerability in the grant helper (polkit-grant-helper2022-05-01
OSV
CVE-2008-1658: Format string vulnerability in the grant helper (polkit-grant-helper2008-04-11

📋Vendor Advisories

2
Red Hat
PolicyKit: format string vulnerability2008-03-22
Debian
CVE-2008-1658: policykit-1 - Format string vulnerability in the grant helper (polkit-grant-helper.c) in Polic...2008

💬Community

1
Bugzilla
CVE-2008-1658 PolicyKit: format string vulnerability2008-04-01