Bugzilla – Bug 933922
VUL-1: CVE-2015-3218: polkit: crash authentication_agent_new with invalid object path in RegisterAuthenticationAgent
Last modified: 2016-04-27 20:21:06 UTC
via redhat bug https://bugzilla.redhat.com/show_bug.cgi?id=1228738 It was reported that polkitd dumps core if you set an invalid object path when calling RegisterAuthenticationAgent. It allows local authenticated users to perform a denial of service attack. Original report: http://lists.freedesktop.org/archives/polkit-devel/2015-May/000420.html SUggested patch is available: http://lists.freedesktop.org/archives/polkit-devel/2015-May/000421.html CVE-2015-3218
bugbot adjusting priority
PolicyKit from SLE11 uses different design, I also checked at the code for similar patterns, but did not find any.
openSUSE-SU-2015:1734-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 933922,935119,939246,943816 CVE References: CVE-2015-3218,CVE-2015-3255,CVE-2015-3256,CVE-2015-4625 Sources used: openSUSE 13.2 (src): polkit-0.113-3.8.1 openSUSE 13.1 (src): polkit-0.113-9.1
Hi When I update to polkit 0.113-3.8.1 will cause some authorize problems 1. users can't enable or disable WiFi 2. users can't modify personal network settings 3. users can't connect to another available connection downgrade to polkit-0.112-3.5.1, everything is OK I took some screenshots in my blog http://swyear.blogspot.tw/2015/10/20151022-polkit.html please fix these problems Thanks I'm using openSUSE 13.2 with KDE desktop all packages are updated to Oss and Update repositories
can you open a new bug please.
SUSE-SU-2015:1838-1: An update that solves four vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 912889,933922,935119,939246,943816,950114 CVE References: CVE-2015-3218,CVE-2015-3255,CVE-2015-3256,CVE-2015-4625 Sources used: SUSE Linux Enterprise Workstation Extension 12 (src): polkit-0.113-4.1 SUSE Linux Enterprise Software Development Kit 12 (src): polkit-0.113-4.1 SUSE Linux Enterprise Server 12 (src): polkit-0.113-4.1 SUSE Linux Enterprise Desktop 12 (src): polkit-0.113-4.1
openSUSE-SU-2015:1927-1: An update that solves four vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 912889,933922,935119,939246,943816,950114 CVE References: CVE-2015-3218,CVE-2015-3255,CVE-2015-3256,CVE-2015-4625 Sources used: openSUSE Leap 42.1 (src): polkit-0.113-6.1
all done i think