CVE-2013-1062: Race Condition
ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1062?
CVE-2013-1062 is classified as a medium severity vulnerability.
How do I fix CVE-2013-1062?
To fix CVE-2013-1062, update the ubuntu-system-service packages to version 0.2.4.1 or later.
Which versions of Ubuntu are affected by CVE-2013-1062?
CVE-2013-1062 affects Ubuntu 12.04, 12.10, and 13.04 running vulnerable versions of ubuntu-system-service.
What is the impact of CVE-2013-1062?
CVE-2013-1062 allows local users to bypass access restrictions, potentially leading to unauthorized actions.
Who is the vendor for the affected software in CVE-2013-1062?
The affected software in CVE-2013-1062 is provided by Michael Vogt and Canonical for Ubuntu.