LWN.net Logo

PolicyKit: authentication bypass

Package(s):PolicyKit CVE #(s):CVE-2008-1658
Created:April 9, 2008 Updated:April 17, 2008
Description:

From the Red Hat bugzilla entry:

Format string vulnerability was discovered in the PolicyKit grant helper. User may specify password with formatting sequences and cause polkit-grant-helper to crash or bypass authentication.

Alerts:
Fedora FEDORA-2008-2987 2008-04-08
Mandriva MDVSA-2008:087 2008-04-16

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.