CVE-2013-1062

Publication date 18 September 2013

Last updated 24 July 2024


Ubuntu priority

ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Status

Package Ubuntu Release Status
ubuntu-system-service 13.04 raring
Fixed 0.2.4.1
12.10 quantal
Fixed 0.2.3.1
12.04 LTS precise
Fixed 0.2.2.1
10.04 LTS lucid Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-1962-1
    • ubuntu-system-service vulnerability
    • 18 September 2013

Other references