Lucene search

K
centosCentOS ProjectCESA-2013:1282
HistorySep 24, 2013 - 8:31 p.m.

rtkit security update

2013-09-2420:31:04
CentOS Project
lists.centos.org
62

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

CentOS Errata and Security Advisory CESA-2013:1282

RealtimeKit is a D-Bus system service that changes the scheduling policy of
user processes/threads to SCHED_RR (that is, realtime scheduling mode) on
request. It is intended to be used as a secure mechanism to allow real-time
scheduling to be used by normal user processes.

It was found that RealtimeKit communicated with PolicyKit for authorization
using a D-Bus API that is vulnerable to a race condition. This could have
led to intended PolicyKit authorizations being bypassed. This update
modifies RealtimeKit to communicate with PolicyKit via a different API that
is not vulnerable to the race condition. (CVE-2013-4326)

All rtkit users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2013-September/082117.html

Affected packages:
rtkit

Upstream details at:
https://access.redhat.com/errata/RHSA-2013:1282

OSVersionArchitecturePackageVersionFilename
CentOS6i686rtkit< 0.5-2.el6_4rtkit-0.5-2.el6_4.i686.rpm
CentOS6x86_64rtkit< 0.5-2.el6_4rtkit-0.5-2.el6_4.x86_64.rpm

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%