
3/10/2013

8/10/2013
CVE-2013-1062: Race Condition
First published: Thu Oct 03 2013(Updated: )
ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Ubuntu | =13.04 | |
Ubuntu System Service | =0.2.2 | |
Ubuntu System Service | =0.2.3 | |
Ubuntu System Service | =0.2.4 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is the severity of CVE-2013-1062?
CVE-2013-1062 is classified as a medium severity vulnerability.
How do I fix CVE-2013-1062?
To fix CVE-2013-1062, update the ubuntu-system-service packages to version 0.2.4.1 or later.
Which versions of Ubuntu are affected by CVE-2013-1062?
CVE-2013-1062 affects Ubuntu 12.04, 12.10, and 13.04 running vulnerable versions of ubuntu-system-service.
What is the impact of CVE-2013-1062?
CVE-2013-1062 allows local users to bypass access restrictions, potentially leading to unauthorized actions.
Who is the vendor for the affected software in CVE-2013-1062?
The affected software in CVE-2013-1062 is provided by Michael Vogt and Canonical for Ubuntu.
- agent/type
- agent/references
- agent/last-modified-date
- agent/first-publish-date
- agent/severity
- agent/weakness
- agent/author
- agent/description
- agent/event
- agent/tags
- agent/softwarecombine
- collector/nvd-index
- agent/software-canonical-lookup-request
- vendor/canonical
- canonical/ubuntu
- version/ubuntu/12.04
- version/ubuntu/12.10
- version/ubuntu/13.04
- vendor/michael vogt
- canonical/ubuntu system service
- version/ubuntu system service/0.2.2
- version/ubuntu system service/0.2.3
- version/ubuntu system service/0.2.4
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203