4.6
CVSSv2

CVE-2013-1064

Published: 03/10/2013 Updated: 18/07/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

apt-xapian-index prior to 0.45ubuntu2.1, 0.44ubuntu7.1, and 0.44ubuntu5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical apt-xapian-index 0.44ubuntu7.1

canonical apt-xapian-index 0.44ubuntu5.1

canonical apt-xapian-index

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

canonical ubuntu linux 13.04

Vendor Advisories

Debian Bug report logs - #724837 apt-xapian-index: unsafe polkit usage Package: apt-xapian-index; Maintainer for apt-xapian-index is Debian QA Group <packages@qadebianorg>; Source for apt-xapian-index is src:apt-xapian-index (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 28 Sep 2013 15:3 ...
apt-xapian-index could be tricked into bypassing polkit authorizations ...