RHSA-2018:1224: Moderate: PackageKit security update
PackageKit is a D-Bus abstraction layer that allows the session user to manage packages in a secure way using a cross-distribution, cross-architecture API.Security Fix(es): PackageKit: authentication bypass allows to install signed packages without administrator privileges (CVE-2018-1106) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.Red Hat would like to thank Matthias Gerstner (SUSE) for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:1224?
The severity of RHSA-2018:1224 is classified as moderate.
What vulnerabilities does RHSA-2018:1224 address?
RHSA-2018:1224 addresses an authentication bypass vulnerability in PackageKit that allows installation of signed packages without administrator privileges.
How do I fix RHSA-2018:1224?
To fix RHSA-2018:1224, update the PackageKit package to the latest version provided by your distribution.
What is PackageKit in the context of RHSA-2018:1224?
PackageKit is a D-Bus abstraction layer that allows users to manage software packages securely across different distributions.
Who is affected by RHSA-2018:1224?
Any user or system utilizing the vulnerable versions of PackageKit is at risk from the issues detailed in RHSA-2018:1224.