PublicDateAtUSN: 2013-09-18 Candidate: CVE-2013-1063 PublicDate: 2013-10-03 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1063 https://ubuntu.com/security/notices/USN-1963-1 Description: usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_usb-creator: upstream_usb-creator: needs-triage lucid_usb-creator: ignored (reached end-of-life) precise_usb-creator: released (0.2.38.2) quantal_usb-creator: released (0.2.40ubuntu2) raring_usb-creator: released (0.2.47.1) devel_usb-creator: released (0.2.49)