Integer Overflow Vulnerability in PolicyKit Affects Local User Privileges
CVE-2015-4625

Currently unrated

Key Information:

Vendor
CVE Published:
26 October 2015

Summary

The vulnerability exists in the authentication_agent_new_cookie function in PolicyKit prior to version 0.113. An integer overflow issue permits local users to create a high volume of connections, leading to the generation of duplicate cookie values. This flaw can be exploited to escalate privileges on affected systems, potentially enabling unauthorized access to sensitive resources.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.