CVE-2015-3255: Medium severity Polkit Project Polkit vulnerability
It was reported that if polkit, while reading action descriptions from /usr/share/polkit-1/actions, encounters a duplicate action ID, it corrupts the heap. The effects of corruption are e.g. visible on stderr as frequent use of unrelated strings when running polkit without --no-debug.
Presumably a local attacker might be able to manipulate polkit’s heap enough to achieve privilege escalation through this.
Upstream bug: https://bugs.freedesktop.org/showbug.cgi?id=83590 Upstream patch is attached.
Other sources
The polkitbackendactionpoolinit function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2015-3255?
CVE-2015-3255 is a vulnerability in PolicyKit that might allow local users to gain privileges via duplicate action IDs in action descriptions.
What is the severity of CVE-2015-3255?
CVE-2015-3255 has a severity level of medium with a CVSS score of 4.6.
How does CVE-2015-3255 affect Red Hat Polkit?
Red Hat Polkit versions up to and including 0.112 are affected by CVE-2015-3255.
How can I fix the CVE-2015-3255 vulnerability in Ubuntu's policykit-1 package?
To fix the CVE-2015-3255 vulnerability in Ubuntu's policykit-1 package, update to version 0.105-11ubuntu1 or a higher version.
Where can I find more information about CVE-2015-3255?
You can find more information about CVE-2015-3255 at the following references: [SecurityTracker](http://www.securitytracker.com/id/1035023), [Gentoo GLSA](https://security.gentoo.org/glsa/201611-07), [Ubuntu USN](https://usn.ubuntu.com/3717-2/).