{
  "threat_severity" : "Moderate",
  "public_date" : "2015-07-02T00:00:00Z",
  "bugzilla" : {
    "description" : "polkit: Memory corruption via javascript rule evaluation",
    "id" : "1245684",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1245684"
  },
  "cvss" : {
    "cvss_base_score" : "4.4",
    "cvss_scoring_vector" : "AV:L/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "details" : [ "PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to \"javascript rule evaluation.\"", "A denial of service flaw was found in how polkit handled authorization requests. A local, unprivileged user could send malicious requests to polkit, which could then cause the polkit daemon to corrupt its memory and crash." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2016-02-16T00:00:00Z",
    "advisory" : "RHSA-2016:0189",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "polkit-0:0.112-6.el7_2"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "polkit",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2015-3256\nhttps://nvd.nist.gov/vuln/detail/CVE-2015-3256" ],
  "name" : "CVE-2015-3256",
  "csaw" : false
}