Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.882896
Category:CentOS Local Security Checks
Title:CentOS Update for PackageKit CESA-2018:1224 centos7
Summary:Check the version of PackageKit
Description:Summary:
Check the version of PackageKit

Vulnerability Insight:
PackageKit is a D-Bus abstraction layer that allows the session user to
manage packages in a secure way using a cross-distribution,
cross-architecture API.

Security Fix(es):

* PackageKit: authentication bypass allows to install signed packages
without administrator privileges (CVE-2018-1106)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

Red Hat would like to thank Matthias Gerstner (SUSE) for reporting this
issue.

Affected Software/OS:
PackageKit on CentOS 7

Solution:
Please install the updated packages.

CVSS Score:
2.1

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1106
Debian Security Information: DSA-4207 (Google Search)
https://www.debian.org/security/2018/dsa-4207
http://www.openwall.com/lists/oss-security/2018/04/23/3
RedHat Security Advisories: RHSA-2018:1224
https://access.redhat.com/errata/RHSA-2018:1224
https://usn.ubuntu.com/3634-1/
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.