CVE-2008-1658

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
11/04/2008
Last modified:
09/04/2025

Description

Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in a password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freedesktop:policykit:*:*:*:*:*:*:*:* 0.7 (including)
cpe:2.3:a:freedesktop:policykit:0.6:*:*:*:*:*:*:*