4.6
CVSSv2

CVE-2013-1066

Published: 03/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

language-selector 0.110.x prior to 0.110.1, 0.90.x prior to 0.90.1, and 0.79.x prior to 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Vulnerable Product Search on Vulmon Subscribe to Product

ubuntu developers language-selector 0.79.1

ubuntu developers language-selector 0.79.2

ubuntu developers language-selector 0.79.3

ubuntu developers language-selector 0.90

ubuntu developers language-selector 0.110

ubuntu developers language-selector 0.79

canonical ubuntu linux 13.04

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

Vendor Advisories

language-selector could be tricked into bypassing polkit authorizations ...