Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1116
HistoryJul 10, 2018 - 3:48 p.m.

CVE-2018-1116

2018-07-1015:48:45
redhat.com
access.redhat.com
13

0.001 Low

EPSS

Percentile

29.3%

It was found that Polkit’s CheckAuthorization and RegisterAuthenticationAgent D-Bus calls did not validate the client provided UID. A specially crafted program could use this flaw to submit arbitrary UIDs, triggering various denial of service or minor disclosures, such as which authentication is cached in the victim’s session.