CVE-2015-3218: Null Pointer Dereference
Published Oct 26, 2015
·Updated
Last updated 24 July 2024
Other sources
The authenticationagentnew function in polkitbackend/polkitbackendin ...
— Debian
Affected Software
2 affected componentsFixes available
Polkit Project Polkit<=0.112
debian/policykit-1
0.105-31+deb11u1122-3126-2127-2
Remediation
Event History
Oct 26, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:08 PM
Description
Sep 20, 2024
Data Sourced
via Ubuntu·12:49 AM
RemedyDescriptionSeverityAffected Software
Feb 18, 2026
Data Sourced
via Debian·10:24 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2015-3218?
CVE-2015-3218 is a vulnerability in PolicyKit that allows local users to cause a denial of service by calling RegisterAuthenticationAgent with an invalid object path, resulting in a NULL pointer dereference and polkitd daemon crash.
2
How does CVE-2015-3218 affect Red Hat Polkit?
Red Hat Polkit before version 0.113 is affected by CVE-2015-3218.
3
Which versions of Ubuntu's policykit-1 package are affected by CVE-2015-3218?
CVE-2015-3218 affects policykit-1 package versions 0.105-4ubuntu3.14.04.2 and 0.105-11.
4
Which versions of Debian's policykit-1 package are affected by CVE-2015-3218?
CVE-2015-3218 affects policykit-1 package versions 0.105-25+deb10u1, 0.105-31+deb11u1, 122-3, and 123-3.
5
What is the severity of CVE-2015-3218?
CVE-2015-3218 has a low severity rating with a value of 2.1.