Excessive privileges In policykit-1
Description
The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 0.105-12 | ||
debian 11 | 0.105-12 | ||
debian 13 | 0.105-12 | ||
debian 14 | 0.105-12 | ||
rpm rhel6 | - | - | |
rpm rhel7 | - | - |
Aliases
1. 2. 3. 4. 5.