Lucene search

K
cvelistCanonicalCVELIST:CVE-2013-1062
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1062

2022-10-0316:14:48
canonical
www.cve.org
6
ubuntu
system
service
communication
vulnerability
d-bus
polkit
access
restrictions
local users
race condition

AI Score

6.4

Confidence

High

EPSS

0

Percentile

5.1%

ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.