CVE-2013-1061
published 2013-10-03CVE-2013-1061: dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus…
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.36%
28.2th percentile
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | software-properties | >= 0 < 0.92.18 | 0.92.18 |
| canonical | software-properties | >= 0 < 0.92.18 | 0.92.18 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | software-properties | < software-properties 0.92.18 (bookworm) | software-properties 0.92.18 (bookworm) |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
| marc_deslauriers | software-properties | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f8vv-fqj4-phcp: dbus/SoftwarePropertiesDBus
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2013-1061 [HIGH] GHSA-f8vv-fqj4-phcp: dbus/SoftwarePropertiesDBus
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
OSV
CVE-2013-1061: dbus/SoftwarePropertiesDBus
osv·2013-10-03·CVSS 4.6
CVE-2013-1061 [MEDIUM] CVE-2013-1061: dbus/SoftwarePropertiesDBus
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Ubuntu
Software Properties vulnerability
vendor_ubuntu·2013-09-18
CVE-2013-1061 Software Properties vulnerability
Title: Software Properties vulnerability
Summary: Software Properties could be tricked into bypassing polkit authorizations.
It was discovered that Software Properties was using polkit in an unsafe
manner. A local attacker could possibly use this issue to bypass intended
polkit authorizations.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2013-1061: software-properties - dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, ...
vendor_debian·2013·CVSS 4.6
CVE-2013-1061 [MEDIUM] CVE-2013-1061: software-properties - dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, ...
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Scope: local
bookworm: resolved (fixed in 0.92.18)
bullseye: resolved (fixed in 0.92.18)
sid: resolved (fixed in 0.92.18)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://launchpadlibrarian.net/150156695/software-properties_0.92.17.2_0.92.17.3.diff.gzhttp://secunia.com/advisories/54909http://www.ubuntu.com/usn/USN-1960-1https://exchange.xforce.ibmcloud.com/vulnerabilities/87381https://launchpad.net/ubuntu/+source/software-properties/0.82.7.5https://launchpad.net/ubuntu/+source/software-properties/0.92.17.3https://launchpad.net/ubuntu/+source/software-properties/0.92.9.3http://launchpadlibrarian.net/150156695/software-properties_0.92.17.2_0.92.17.3.diff.gzhttp://secunia.com/advisories/54909http://www.ubuntu.com/usn/USN-1960-1https://exchange.xforce.ibmcloud.com/vulnerabilities/87381https://launchpad.net/ubuntu/+source/software-properties/0.82.7.5https://launchpad.net/ubuntu/+source/software-properties/0.92.17.3https://launchpad.net/ubuntu/+source/software-properties/0.92.9.3
2013-10-03
Published