CVE-2018-1106
published 2018-04-23CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local…
PriorityP426medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.39%
31.6th percentile
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | packagekit | < packagekit 1.1.10-1 (bookworm) | packagekit 1.1.10-1 (bookworm) |
| packagekit_project | packagekit | < 1.1.10 | 1.1.10 |
| red_hat_inc | packagekit | — | — |
| red_hat_inc | packagekit | >= 0 < 1.1.10-1 | 1.1.10-1 |
| red_hat_inc | packagekit | >= 0 < 1.1.10-1 | 1.1.10-1 |
| red_hat_inc | packagekit | >= 0 < 1.1.10-1 | 1.1.10-1 |
| red_hat_inc | packagekit | >= 0 < 1.1.10-1 | 1.1.10-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PackageKit vulnerability
vendor_ubuntu·2018-04-24
CVE-2018-1106 PackageKit vulnerability
Title: PackageKit vulnerability
Summary: PackageKit could be made to install or run programs as an administrator.
Matthias Gerstner discovered that PackageKit incorrectly handled
authentication. A local attacker could possibly use this issue to install
arbitrary packages and escalate privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
PackageKit: authentication bypass allows to install signed packages without administrator privileges
vendor_redhat·2018-04-23·CVSS 5.5
CVE-2018-1106 [MEDIUM] CWE-287 PackageKit: authentication bypass allows to install signed packages without administrator privileges
PackageKit: authentication bypass allows to install signed packages without administrator privileges
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
An authentication bypass flaw has been found in PackageKit that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
Package: PackageKit (Red Hat Enterprise Linux 6) - Not affected
Package: PackageKit (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-1106: packagekit - An authentication bypass flaw has been found in PackageKit before 1.1.10 that al...
vendor_debian·2018·CVSS 5.5
CVE-2018-1106 [MEDIUM] CVE-2018-1106: packagekit - An authentication bypass flaw has been found in PackageKit before 1.1.10 that al...
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
Scope: local
bookworm: resolved (fixed in 1.1.10-1)
bullseye: resolved (fixed in 1.1.10-1)
forky: resolved (fixed in 1.1.10-1)
sid: resolved (fixed in 1.1.10-1)
trixie: resolved (fixed in 1.1.10-1)
GHSA
GHSA-9pvg-w7xf-pgq7: An authentication bypass flaw has been found in PackageKit before 1
ghsa_unreviewed·2022-05-13
CVE-2018-1106 [MEDIUM] CWE-287 GHSA-9pvg-w7xf-pgq7: An authentication bypass flaw has been found in PackageKit before 1
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
OSV
CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 1
osv·2018-04-23·CVSS 5.5
CVE-2018-1106 [MEDIUM] CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 1
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2018/04/23/3https://access.redhat.com/errata/RHSA-2018:1224https://bugzilla.redhat.com/show_bug.cgi?id=1565992https://usn.ubuntu.com/3634-1/https://www.debian.org/security/2018/dsa-4207http://www.openwall.com/lists/oss-security/2018/04/23/3https://access.redhat.com/errata/RHSA-2018:1224https://bugzilla.redhat.com/show_bug.cgi?id=1565992https://usn.ubuntu.com/3634-1/https://www.debian.org/security/2018/dsa-4207
2018-04-23
Published