CVE-2018-1106Improper Authentication in Project Packagekit

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 92.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 23
Latest updateMay 13

Description

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Also affects: Debian Linux 9.0, Ubuntu Linux 17.10, Enterprise Linux 7.6, 7.5

🔴Vulnerability Details

3
GHSA
GHSA-9pvg-w7xf-pgq7: An authentication bypass flaw has been found in PackageKit before 12022-05-13
CVEList
CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 12018-04-23
OSV
CVE-2018-1106: An authentication bypass flaw has been found in PackageKit before 12018-04-23

📋Vendor Advisories

3
Ubuntu
PackageKit vulnerability2018-04-24
Red Hat
PackageKit: authentication bypass allows to install signed packages without administrator privileges2018-04-23
Debian
CVE-2018-1106: packagekit - An authentication bypass flaw has been found in PackageKit before 1.1.10 that al...2018

💬Community

1
Bugzilla
CVE-2018-1106 PackageKit: authentication bypass allows to install signed packages without administrator privileges2018-04-11
CVE-2018-1106 — Improper Authentication | cvebase