ZeroHour

CVE-2018-1106

CVSS 3.0
5.5 medium
EPSS
<1%p32
Published
()
Modified
Description

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.

Vendors
packagekit projectredhatcanonicaldebian
Products
packagekit, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, ubuntu linux, debian linux
Weakness
CWE-287
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.