CVE-2015-4625
NONE EPSS 32.4%
Published Oct 26, 201510y ago · Modified Jun 17, 20262w ago
Published Oct 26, 2015 10y ago
Last Modified Jun 17, 2026 2w ago
Description
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
Threat Intelligence
EPSS Exploit Probability
32.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-189
Affected Products 5
| Vendor | Product | Version | Range |
|---|---|---|---|
| fedoraproject | fedora | 21 | any |
| fedoraproject | fedora | 22 | any |
| opensuse | opensuse | 13.1 | any |
| opensuse | opensuse | 13.2 | any |
| polkit_project | polkit | * | ≤0.112 |
References 12
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161721.html
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162294.html
- lists.freedesktop.org http://lists.freedesktop.org/archives/polkit-devel/2015-July/000432.html
- lists.freedesktop.org http://lists.freedesktop.org/archives/polkit-devel/2015-June/000427.html
- lists.freedesktop.org http://lists.freedesktop.org/archives/polkit-devel/2015-May/000419.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00010.html
- lists.opensuse.org http://lists.opensuse.org/opensuse-updates/2015-11/msg00042.html
- openwall.com http://www.openwall.com/lists/oss-security/2015/06/08/3
- openwall.com http://www.openwall.com/lists/oss-security/2015/06/09/1
- openwall.com http://www.openwall.com/lists/oss-security/2015/06/16/21
- securityfocus.com http://www.securityfocus.com/bid/75267
- securitytracker.com http://www.securitytracker.com/id/1035023
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.