Bug#1109334: policykit-1: CVE-2025-7519

2025-07-16 Thread Moritz Mühlenhoff
On Tue, Jul 15, 2025 at 02:49:55PM +0100, Simon McVittie wrote: > On Tue, 15 Jul 2025 at 14:29:13 +0200, Moritz Mühlenhoff wrote: > > The following vulnerability was published for policykit-1. > > > > CVE-2025-7519[0]: > > | When processing an XML policy with 32 or > > | more nested elements in de

Bug#1109334: policykit-1: CVE-2025-7519

2025-07-15 Thread Simon McVittie
On Tue, 15 Jul 2025 at 14:29:13 +0200, Moritz Mühlenhoff wrote: The following vulnerability was published for policykit-1. CVE-2025-7519[0]: | When processing an XML policy with 32 or | more nested elements in depth [...] | | To exploit | this flaw, a high-privilege account is needed Honest

Bug#1109334: policykit-1: CVE-2025-7519

2025-07-15 Thread Moritz Mühlenhoff
Package: policykit-1 X-Debbugs-CC: t...@security.debian.org Severity: normal Tags: security Hi, The following vulnerability was published for policykit-1. CVE-2025-7519[0]: | A flaw was found in polkit. When processing an XML policy with 32 or | more nested elements in depth, an out-of-bounds wr