CVE-2013-1065
Published Oct 3, 2013
Last updated 11 years ago
Overview
- Description
- backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
- Source
- security@ubuntu.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:martin_pitt:jockey:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07090452-BD89-4AB1-A076-A208128456D9", "versionEndIncluding": "0.9.7-0ubuntu7.10" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C0822612-612D-4E8E-A34C-E57F4938D174" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45D51D4E-0C2C-45A2-A17A-30112193C0C0" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A53467B-E4E0-4957-ABEE-EAA8A817A9D6" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "952DE0CA-2F7E-4F96-8B18-64256814E7CE" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1A4E3BB-4584-4086-9E65-FC628B8E0DEA" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65962113-C6EC-4F95-A67C-1F9E931C3E5F" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E6B6809-7513-494F-854C-F4E42377323B" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E22007E-7BCA-489F-A2C0-B599FB66981D" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AEE40975-8F46-4BC7-8152-580C699DEA60" }, { "criteria": "cpe:2.3:a:martin_pitt:jockey:0.9.7-0ubuntu7.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11916487-4022-4760-99D2-D2DF9CA587B7" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5D324C4-97C7-49D3-A809-9EAD4B690C69" } ], "operator": "OR" } ] } ]