Integer Overflow Vulnerability in PolicyKit Affects Local User Privileges
CVE-2015-4625
Currently unrated
Summary
The vulnerability exists in the authentication_agent_new_cookie function in PolicyKit prior to version 0.113. An integer overflow issue permits local users to create a high volume of connections, leading to the generation of duplicate cookie values. This flaw can be exploited to escalate privileges on affected systems, potentially enabling unauthorized access to sensitive resources.
References
Timeline
Vulnerability published
Vulnerability Reserved