Bug 933922 - (CVE-2015-3218) VUL-1: CVE-2015-3218: polkit: crash authentication_agent_new with invalid object path in RegisterAuthenticationAgent
(CVE-2015-3218)
VUL-1: CVE-2015-3218: polkit: crash authentication_agent_new with invalid obj...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/117358/
CVSSv2:RedHat:CVE-2015-3218:2.1:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-06-08 10:58 UTC by Marcus Meissner
Modified: 2016-04-27 20:21 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2015-06-08 10:58:13 UTC
via redhat bug https://bugzilla.redhat.com/show_bug.cgi?id=1228738


It was reported that polkitd dumps core if you set an invalid object
path when calling RegisterAuthenticationAgent.
It allows local authenticated users to perform a denial of service attack.
Original report: http://lists.freedesktop.org/archives/polkit-devel/2015-May/000420.html
SUggested patch is available: http://lists.freedesktop.org/archives/polkit-devel/2015-May/000421.html

CVE-2015-3218
Comment 1 Swamp Workflow Management 2015-06-08 22:01:21 UTC
bugbot adjusting priority
Comment 2 Marcus Meissner 2015-10-02 11:29:24 UTC
PolicyKit from SLE11 uses different design, I also checked at the code for similar patterns, but did not find any.
Comment 4 Swamp Workflow Management 2015-10-14 08:10:21 UTC
openSUSE-SU-2015:1734-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 933922,935119,939246,943816
CVE References: CVE-2015-3218,CVE-2015-3255,CVE-2015-3256,CVE-2015-4625
Sources used:
openSUSE 13.2 (src):    polkit-0.113-3.8.1
openSUSE 13.1 (src):    polkit-0.113-9.1
Comment 6 Ray chen 2015-10-23 18:00:32 UTC
Hi 
When I update to polkit 0.113-3.8.1 will cause some authorize problems
1. users can't enable or disable WiFi
2. users can't modify personal network settings
3. users can't connect to another available connection
downgrade to polkit-0.112-3.5.1, everything is OK
I took some screenshots in my blog
http://swyear.blogspot.tw/2015/10/20151022-polkit.html
please fix these problems
Thanks

I'm using openSUSE 13.2 with KDE desktop
all packages are updated to Oss and Update repositories
Comment 7 Marcus Meissner 2015-10-23 18:18:36 UTC
can you open a new bug please.
Comment 8 Swamp Workflow Management 2015-10-28 11:10:44 UTC
SUSE-SU-2015:1838-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 912889,933922,935119,939246,943816,950114
CVE References: CVE-2015-3218,CVE-2015-3255,CVE-2015-3256,CVE-2015-4625
Sources used:
SUSE Linux Enterprise Workstation Extension 12 (src):    polkit-0.113-4.1
SUSE Linux Enterprise Software Development Kit 12 (src):    polkit-0.113-4.1
SUSE Linux Enterprise Server 12 (src):    polkit-0.113-4.1
SUSE Linux Enterprise Desktop 12 (src):    polkit-0.113-4.1
Comment 9 Swamp Workflow Management 2015-11-06 17:11:25 UTC
openSUSE-SU-2015:1927-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 912889,933922,935119,939246,943816,950114
CVE References: CVE-2015-3218,CVE-2015-3255,CVE-2015-3256,CVE-2015-4625
Sources used:
openSUSE Leap 42.1 (src):    polkit-0.113-6.1
Comment 10 Marcus Meissner 2015-11-27 10:08:41 UTC
all done i think