1 |
type: security |
2 |
subject: Updated polkit package fixes security vulnerabilities |
3 |
CVE: |
4 |
- CVE-2015-3218 |
5 |
- CVE-2015-3255 |
6 |
- CVE-2015-3256 |
7 |
- CVE-2015-4625 |
8 |
src: |
9 |
4: |
10 |
core: |
11 |
- polkit-0.113-1.mga4 |
12 |
5: |
13 |
core: |
14 |
- polkit-0.113-1.mga5 |
15 |
description: | |
16 |
Local privilege escalation in polkit before 0.113 due to predictable |
17 |
authentication session cookie values (CVE-2015-4625). |
18 |
|
19 |
Various memory corruption vulnerabilities in polkit before 0.113 in the |
20 |
use of the JavaScript interpreter, possibly leading to local privilege |
21 |
escalation (CVE-2015-3256). |
22 |
|
23 |
Memory corruption vulnerability in polkit before 0.113 in handling |
24 |
duplicate action IDs, possibly leading to local privilege escalation |
25 |
(CVE-2015-3255). |
26 |
|
27 |
Denial of service issue in polkit before 0.113 which allowed any local |
28 |
user to crash polkitd (CVE-2015-3218). |
29 |
references: |
30 |
- https://bugs.mageia.org/show_bug.cgi?id=16135 |
31 |
- http://lists.freedesktop.org/archives/polkit-devel/2015-July/000432.html |
32 |
ID: MGASA-2015-0262 |