HIGH · 7.2

CVE-2013-4288

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is perfo...

Vulnerability Description

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
OpensuseOpensuse12.2
Polkit ProjectPolkit< 0.112.1
CanonicalUbuntu Linux10.04
RedhatEnterprise Linux6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4288?

CVE-2013-4288 is a vulnerability with a CVSS score of 7.2 (HIGH). Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is perfo...

How severe is CVE-2013-4288?

CVE-2013-4288 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4288?

Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Opensuse, Polkit Project Polkit, Canonical Ubuntu Linux, Redhat Enterprise Linux.