CVE-2013-4311 — Race Condition in Redhat Libvirt
9 documents8 sources
Severity
4.6MEDIUMNVD
CNA7.2OSV7.2
EPSS
0.0%
top 93.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 3
Latest updateMay 14
Description
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4
Affected Packages2 packages
Also affects: Ubuntu Linux 10.04, 12.04, 12.10, 13.04, Enterprise Linux 6.0