VDB

ALINUX2-SA-2019%3A0013

ALINUX2-SA-2019%3A0013 PUBLISHED CVSS 7.300000190734863 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-6133: In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.

Risk Scores

CVSS 3.0
7.300000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alibaba Cloudpolkit

Timeline

  • Mar 11, 2019 CVE Published
  • Mar 11, 2019 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›