CVE-2013-1066: Race Condition
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1066?
CVE-2013-1066 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2013-1066?
To fix CVE-2013-1066, update the language-selector package to version 0.110.1 or later.
What software is affected by CVE-2013-1066?
CVE-2013-1066 affects the language-selector versions 0.79.x before 0.79.4, 0.90.x before 0.90.1, and 0.110.x before 0.110.1.
Can CVE-2013-1066 be exploited remotely?
CVE-2013-1066 cannot be exploited remotely as it requires local access to the system.
What is the nature of the vulnerability in CVE-2013-1066?
CVE-2013-1066 involves a race condition in Polkit communication that allows local users to bypass access restrictions.