MEDIUM
ubuntu-system-service 0.2.4 before 0.2.4.1
Published Oct 3, 2013
4.6
MEDIUMCVSS 2.0
EPSS 0.36%
Description
ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected products
No data.
Configuration 1
OR
- 12.04
- 12.10
- 13.04
Configuration 2
OR
- 0.2.2
- 0.2.3
- 0.2.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://secunia.com/advisories/54907 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.ubuntu.com/usn/USN-1962-1 vendor-advisoryx_refsource_UBUNTUVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1102 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/54907 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.ubuntu.com/usn/USN-1962-1 | vendor-advisoryx_refsource_UBUNTUVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1102 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Oct 3, 2013
Updated Sep 16, 2024
Reserved Jan 11, 2013
Link CVE-2013-1062
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-1102 Assigner canonical
Published Oct 3, 2013
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2013-1102