CVE-2018-8885Race Condition in Screen-resolution-extra

CWE-362Race Condition4 documents4 sources
Severity
7.0HIGHNVD
EPSS
0.0%
top 88.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateMay 14

Description

screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages2 packages

Also affects: Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

2
GHSA
GHSA-wpjr-f7r3-fjvc: screenresolution-mechanism in screen-resolution-extra 02022-05-14
OSV
CVE-2018-8885: screenresolution-mechanism in screen-resolution-extra 02018-03-26

📋Vendor Advisories

1
Ubuntu
Screen Resolution Extra vulnerability2018-03-26