HomeOpensuseCVE-2013-4288

CVE-2013-4288

UNKNOWN
7.2CVSS
Published: 2013-10-03
Updated: 2025-04-11
AI Analysis

Description

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

CVSS Metrics

Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector
local
Access Cmplx
low
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-362

Metadata

Primary Vendor
OPENSUSE
Published
10/3/2013
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

opensuse : opensuseopensuse : opensusepolkit_project : polkitcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxredhat : enterprise_linux

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2013-4288 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com