Candidate: CVE-2017-7572 PublicDate: 2017-04-06 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7572 Description: The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorization method, the owner of a process requesting a polkit operation is checked by polkitd via /proc//status, by which time the requesting process may have been replaced by a different process with the same PID that has different privileges then the original requester. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_backintime: upstream: https://github.com/bit-team/backintime/commit/7f208dc547f569b689c888103e3b593a48cd1869 upstream_backintime: released (1.1.12-2) precise_backintime: ignored (reached end-of-life) precise/esm_backintime: DNE (precise was needed) trusty_backintime: ignored (reached end-of-life) trusty/esm_backintime: DNE (trusty was needed) vivid/stable-phone-overlay_backintime: DNE vivid/ubuntu-core_backintime: DNE xenial_backintime: released (1.1.2-2~build0.16.04.1) yakkety_backintime: ignored (reached end-of-life) zesty_backintime: ignored (reached end-of-life) artful_backintime: ignored (reached end-of-life) bionic_backintime: not-affected (1.1.12-2) cosmic_backintime: not-affected (1.1.12-2) disco_backintime: not-affected (1.1.12-2) devel_backintime: not-affected (1.1.12-2)