CVE-2018-19788Improper Input Validation in Project Polkit

Severity
8.8HIGHNVD
EPSS
59.6%
top 1.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3
Latest updateMay 14

Description

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4569-2jp2-r7vf: A flaw was found in PolicyKit (aka polkit) 02022-05-14
CVEList
CVE-2018-19788: A flaw was found in PolicyKit (aka polkit) 02018-12-03
OSV
CVE-2018-19788: A flaw was found in PolicyKit (aka polkit) 02018-12-03

📋Vendor Advisories

4
Ubuntu
PolicyKit vulnerability2019-01-16
Ubuntu
PolicyKit vulnerability2019-01-16
Red Hat
polkit: Improper handling of user with uid > INT_MAX leading to authentication bypass2018-12-03
Debian
CVE-2018-19788: policykit-1 - A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid g...2018

💬Community

2
Bugzilla
CVE-2018-19788 polkit: Improper handling of user with uid > INT_MAX leading to authentication bypass2018-12-04
Bugzilla
CVE-2018-19788 polkit: Improper handling of user with uid > INT_MAX leading to authentication bypass [fedora-all]2018-12-04
CVE-2018-19788 — Improper Input Validation | cvebase