Security Advisory

CVE-2013-1062

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2013-10-03 21:00:00
Last updated 2024-09-16 18:49:03
Assigner canonical
State PUBLISHED

Description

ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.