CVE-2018-8885: Race Condition
screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService.checkpermission call.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/screen-resolution-extrato a version that resolves this vulnerability.Fixed in 0.17.1.1 - Upgrade
Upgrade
ubuntu/screen-resolution-extrato a version that resolves this vulnerability.Fixed in 0.17.1.1~14.04.1 - Upgrade
Upgrade
ubuntu/screen-resolution-extrato a version that resolves this vulnerability.Fixed in 0.17.1.1~16.04.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-8885?
CVE-2018-8885 is classified as a high severity vulnerability due to its ability to allow local users to bypass access restrictions.
How do I fix CVE-2018-8885?
To fix CVE-2018-8885, upgrade the screen-resolution-extra package to version 0.17.1.1 or later.
Which versions of screen-resolution-extra are affected by CVE-2018-8885?
CVE-2018-8885 affects screen-resolution-extra version 0.17.2 and earlier versions.
Is my system vulnerable to CVE-2018-8885?
If you are running screen-resolution-extra version 0.17.2 or lower, your system is vulnerable to CVE-2018-8885.
What platforms are affected by CVE-2018-8885?
CVE-2018-8885 affects Ubuntu operating systems running the vulnerable versions of the screen-resolution-extra package.