{"schema_version":"1.9.0","id":"CVE-2018-1116","published":"2018-07-10T19:29:00.290Z","modified":"2026-08-20T03:45:06.126608640Z","related":["SUSE-SU-2018:2163-1","SUSE-SU-2018:2165-1","openSUSE-SU-2024:11180-1"],"details":"A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.","affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/polkit/polkit","events":[{"introduced":"0"},{"fixed":"b0a5d0f1a5b835819da630a6d27ed89dd4d7f464"}],"database_specific":{"cpe":"cpe:2.3:a:polkit_project:polkit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.115"}],"source":"CPE_RANGE"}}],"versions":["0.114","0.113","0.112","0.111","0.110","0.109","0.108","0.107","0.106","0.105","0.104","0.103","0.102","0.96","0.101","0.100","0.99","0.98","0.97","0.95","0.94","0.93","0.92","0.91","POLICY_KIT_0_9","POLICY_KIT_0_8","POLICY_KIT_0_7","POLICY_KIT_0_6","POLICY_KIT_0_5","POLICY_KIT_0_4","POLICY_KIT_0_3","start"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1116.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2018/07/msg00042.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201908-14"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3717-2/"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1116"},{"type":"FIX","url":"https://cgit.freedesktop.org/polkit/commit/?id=bc7ffad5364"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*"],"extracted_events":[{"introduced":"12.04"},{"last_affected":"12.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"}]}