CVE-2013-4288
Summary
| CVE | CVE-2013-4288 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-10-03 21:55:00 UTC |
| Updated | 2023-02-13 04:45:00 UTC |
| Description | Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-sec: Re: Fwd: [vs-plain] polkit races |
MLIST |
seclists.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| openSUSE-SU-2013:1527-1: moderate: update for systemd |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| USN-1953-1: polkit vulnerability | Ubuntu |
UBUNTU |
www.ubuntu.com |
Third Party Advisory |
| openSUSE-SU-2013:1617-1: moderate: update for hplip |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| access.redhat.com | CVE-2013-4288 |
MISC |
access.redhat.com |
|
| oss-security - Fwd: [vs-plain] polkit races |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| openSUSE-SU-2013:1528-1: moderate: systemd: bugfix and |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| openSUSE-SU-2013:1620-1: moderate: update for hplip |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| 1002375 – (CVE-2013-4288) CVE-2013-4288 polkit: unix-process subject for authorization is racy |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| 1002375 – (CVE-2013-4288) CVE-2013-4288 polkit: unix-process subject for authorization is racy |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296088 Oracle Solaris 11.4 Support Repository Update (SRU) 9.1.5 Missing (CPUAPR2019)