CVE-2013-1061: Race Condition
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1061?
CVE-2013-1061 has a high severity rating, allowing local users to bypass access restrictions.
How do I fix CVE-2013-1061?
To fix CVE-2013-1061, update the affected software properties package to the latest version as specified in security advisories.
Who is affected by CVE-2013-1061?
CVE-2013-1061 affects users running specific versions of Software Properties on Ubuntu systems.
What causes the vulnerability in CVE-2013-1061?
The vulnerability in CVE-2013-1061 is caused by improper use of D-Bus for communication with a polkit authority.
Is CVE-2013-1061 exploitable remotely?
No, CVE-2013-1061 can only be exploited locally by users on the affected system.