PublicDateAtUSN: 2013-09-18 Candidate: CVE-2013-1062 PublicDate: 2013-10-03 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1062 https://ubuntu.com/security/notices/USN-1962-1 Description: ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ubuntu-system-service: upstream_ubuntu-system-service: needs-triage lucid_ubuntu-system-service: ignored (reached end-of-life) precise_ubuntu-system-service: released (0.2.2.1) quantal_ubuntu-system-service: released (0.2.3.1) raring_ubuntu-system-service: released (0.2.4.1) devel_ubuntu-system-service: released (0.2.5)