Page 2 of 11 results (0.004 seconds)
CVSS: 9.8EPSS: 0%CPEs: 8EXPL: 0

CVE-2013-4288 – polkit: unix-process subject for authorization is racy
https://notcve.org/view.php?id=CVE-2013-4288
18 Sep 2013 — Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck. Condición de carrera en PolicyKit (también conocida como polkit) permite a usuarios locales evadir restricciones PolicyKit intencionadas y obtener privilegios... • http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=1002375 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •