Lucene search

K
nvd[email protected]NVD:CVE-2013-4325
HistorySep 23, 2013 - 10:18 a.m.

CVE-2013-4325

2013-09-2310:18:58
CWE-264
web.nvd.nist.gov
1

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.

Affected configurations

NVD
Node
hplinux_imaging_and_printing_projectMatch1.0
OR
hplinux_imaging_and_printing_projectMatch2.0
OR
hplinux_imaging_and_printing_projectMatch2.7.10
OR
hplinux_imaging_and_printing_projectMatch3.9.2
OR
hplinux_imaging_and_printing_projectMatch3.9.4
OR
hplinux_imaging_and_printing_projectMatch3.9.4b
OR
hplinux_imaging_and_printing_projectMatch3.9.6
OR
hplinux_imaging_and_printing_projectMatch3.9.8
OR
hplinux_imaging_and_printing_projectMatch3.9.10
OR
hplinux_imaging_and_printing_projectMatch3.9.12
OR
hplinux_imaging_and_printing_projectMatch3.10.2
OR
hplinux_imaging_and_printing_projectMatch3.10.5
OR
hplinux_imaging_and_printing_projectMatch3.10.6
OR
hplinux_imaging_and_printing_projectMatch3.10.9
OR
hplinux_imaging_and_printing_projectMatch3.11.1
OR
hplinux_imaging_and_printing_projectMatch3.11.3
OR
hplinux_imaging_and_printing_projectMatch3.11.3a
OR
hplinux_imaging_and_printing_projectMatch3.11.5
OR
hplinux_imaging_and_printing_projectMatch3.11.7
OR
hplinux_imaging_and_printing_projectMatch3.11.10
OR
hplinux_imaging_and_printing_projectMatch3.12.2
OR
hplinux_imaging_and_printing_projectMatch3.12.4
OR
hplinux_imaging_and_printing_projectMatch3.12.6
OR
hplinux_imaging_and_printing_projectMatch3.12.9
OR
hplinux_imaging_and_printing_projectMatch3.12.10
OR
hplinux_imaging_and_printing_projectMatch3.12.10a
OR
hplinux_imaging_and_printing_projectMatch3.12.11
OR
hplinux_imaging_and_printing_projectMatch3.13.2
OR
hplinux_imaging_and_printing_projectMatch3.13.3
OR
hplinux_imaging_and_printing_projectMatch3.13.4
OR
hplinux_imaging_and_printing_projectMatch3.13.5
OR
hplinux_imaging_and_printing_projectMatch3.13.6
OR
hplinux_imaging_and_printing_projectMatch3.13.7
OR
hplinux_imaging_and_printing_projectMatch3.13.8
OR
hplinux_imaging_and_printing_projectMatch3.13.9

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%