Medium severity5.5NVD Advisory· Published Apr 23, 2018· Updated Jun 17, 2026
CVE-2018-1106
CVE-2018-1106
Description
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- Red Hat, Inc./PackageKitv5Range: before 1.1.10
<1.1.10+ 1 more
- (no CPE)range: <1.1.10
- cpe:2.3:a:packagekit_project:packagekit:*:*:*:*:*:*:*:*range: <1.1.10
- osv-coords6 versionspkg:rpm/suse/PackageKit&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/PackageKit&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/PackageKit&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/PackageKit&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/PackageKit&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/opensuse/PackageKit&distro=openSUSE%20Tumbleweed
< 1.1.3-24.6.1+ 5 more
- (no CPE)range: < 1.1.3-24.6.1
- (no CPE)range: < 1.1.3-24.6.1
- (no CPE)range: < 1.1.3-24.6.1
- (no CPE)range: < 1.1.3-24.6.1
- (no CPE)range: < 1.1.3-24.6.1
- (no CPE)range: < 1.2.2-13.2
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2018/04/23/3nvdMailing ListThird Party Advisory
- access.redhat.com/errata/RHSA-2018:1224nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- usn.ubuntu.com/3634-1/nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4207nvdThird Party Advisory
News mentions
0No linked articles in our index yet.