CVE-2015-3218
Published: 26 October 2015
The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.
Priority
Status
Package | Release | Status |
---|---|---|
policykit-1 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(0.105-11)
|
bionic |
Not vulnerable
(0.105-11)
|
|
cosmic |
Not vulnerable
(0.105-11)
|
|
disco |
Not vulnerable
(0.105-11)
|
|
eoan |
Not vulnerable
(0.105-11)
|
|
focal |
Not vulnerable
(0.105-11)
|
|
groovy |
Not vulnerable
(0.105-11)
|
|
hirsute |
Not vulnerable
(0.105-11)
|
|
precise |
Ignored
(end of life)
|
|
trusty |
Released
(0.105-4ubuntu3.14.04.2)
|
|
upstream |
Released
(0.105-11)
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Ignored
(end of life)
|
|
wily |
Not vulnerable
(0.105-11)
|
|
xenial |
Not vulnerable
(0.105-11)
|
|
yakkety |
Not vulnerable
(0.105-11)
|
|
zesty |
Not vulnerable
(0.105-11)
|
|
Patches: upstream: http://cgit.freedesktop.org/polkit/commit/?id=48e646918efb2bf0b3b505747655726d7869f31c |