Description Preview
The integer overflow vulnerability in the authentication_agent_new_cookie function in PolicyKit (polkit) before version 0.113 allows a local user to exploit the issue by creating a large number of connections, which triggers the issuance of a duplicate cookie value. By exploiting this vulnerability, an attacker could potentially gain elevated privileges on the system.
Overview
This vulnerability affects PolicyKit (polkit) versions before 0.113. It was publicly disclosed on May 29, 2015, and assigned the CVE identifier CVE-2015-4625. The vulnerability allows local users to escalate their privileges by exploiting an integer overflow in the authentication_agent_new_cookie function.
Remediation
To remediate this vulnerability, users are advised to update PolicyKit to version 0.113 or later. By upgrading to a patched version, the integer overflow issue in the authentication_agent_new_cookie function is addressed, preventing attackers from exploiting the vulnerability to gain elevated privileges.
References
- [polkit-devel] 20150603 Agent Authentication Question - http://lists.freedesktop.org/archives/polkit-devel/2015-June/000427.html
- 75267 - http://www.securityfocus.com/bid/75267
- FEDORA-2015-11058 - http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161721.html
- openSUSE-SU-2015:1927 - http://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html
- FEDORA-2015-11743 - http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162294.html
- [polkit-devel] 20150702 polkit-0.113 released - http://lists.freedesktop.org/archives/polkit-devel/2015-July/000432.html
- [oss-security] 20150609 Re: CVE request for polkit - http://www.openwall.com/lists/oss-security/2015/06/09/1
- openSUSE-SU-2015:1734 - http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.html
- [oss-security] 20150608 CVE request for polkit - http://www.openwall.com/lists/oss-security/2015/06/08/3
- [polkit-devel] 20150529 Agent Authentication Question - http://lists.freedesktop.org/archives/polkit-devel/2015-May/000419.html
- [oss-security] 20150616 Re: CVE request for polkit - http://www.openwall.com/lists/oss-security/2015/06/16/21
- 1035023 - http://www.securitytracker.com/id/1035023
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Retail TradeRetail Trade
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- Transportation & WarehousingTransportation & Warehousing
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- UtilitiesUtilities
- Accommodation & Food ServicesAccommodation & Food Services
- Other Services (except Public Administration)Other Services (except Public Administration)
- Public AdministrationPublic Administration
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- ConstructionConstruction
- Educational ServicesEducational Services
- InformationInformation
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Wholesale TradeWholesale Trade