Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4288

Опубликовано: 18 сент. 2013
Источник: redhat
CVSS2: 6.9
EPSS Низкий

Описание

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7polkitNot affected
Red Hat Enterprise Linux 6polkitFixedRHSA-2013:127019.09.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1002375polkit: unix-process subject for authorization is racy

EPSS

Процентиль: 7%
0.00033
Низкий

6.9 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

nvd
почти 12 лет назад

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

debian
почти 12 лет назад

Race condition in PolicyKit (aka polkit) allows local users to bypass ...

github
больше 3 лет назад

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

oracle-oval
почти 12 лет назад

ELSA-2013-1270: polkit security update (IMPORTANT)

EPSS

Процентиль: 7%
0.00033
Низкий

6.9 Medium

CVSS2