Versio.io

CVE-2013-4327

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 03-10-2013 11:55
Last modified: - 31-01-2022 06:39
Total changes: - 2

Description

systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Common Vulnerability Scoring System (CVSS)

AV:L/AC:M/Au:N/C:C/I:C/A:C
Low
Attack complexity
Local
Attack vector
High
Availability
High
Confidentiality
High
Integrity
-
Privileges required
-
Scope
-
User interaction
6.9
Base score
3.4
10.0
Exploitability score
Impact score
 

Verification logic

OR
OR
vendor=systemd_project AND product=systemd AND versionEndIncluding=207
OR
vendor=Debian AND product=debian_linux AND version=7.0
OR
vendor=canonical AND product=ubuntu_linux AND version=13.04
 

Reference

 


Keywords

NVD

 

CVE-2013-4327

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.