First published: Thu Oct 03 2013(Updated: )
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | =0.9.12 | |
Redhat Libvirt | =0.10.2 | |
Redhat Libvirt | =0.10.2.1 | |
Redhat Libvirt | =0.10.2.2 | |
Redhat Libvirt | =0.10.2.3 | |
Redhat Libvirt | =0.10.2.4 | |
Redhat Libvirt | =0.10.2.5 | |
Redhat Libvirt | =0.10.2.6 | |
Redhat Libvirt | =0.10.2.7 | |
Redhat Libvirt | =1.0.5 | |
Redhat Libvirt | =1.0.5.1 | |
Redhat Libvirt | =1.0.5.2 | |
Redhat Libvirt | =1.0.5.3 | |
Redhat Libvirt | =1.0.5.4 | |
Redhat Libvirt | =1.0.5.5 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
Canonical Ubuntu Linux | =13.04 | |
Redhat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.