Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-3256
HistoryOct 26, 2015 - 12:00 a.m.

CVE-2015-3256

2015-10-2600:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of
service (memory corruption and polkitd daemon crash) and possibly gain
privileges via unspecified vectors, related to “javascript rule
evaluation.”

Notes

Author Note
sbeattie likely need all the commits between 2015-06-18 and 2015-06-19 plus 2015-06-23 to address issues note that this only affected policykit versions that used javscript via libmozjs, which none of the ubuntu versions do

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%