Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PolicyKit Grant Helper Password Handling Local Format String Vulnerability

PolicyKit is prone to a local format-string vulnerability because it fails to adequately sanitize user-supplied input before passing it to a formatted-printing function.

Successfully exploiting this issue will allow local attackers to bypass authentication or to cause a denial of service. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.

PolicyKit 0.6 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus