// For flags

CVE-2013-4325

hplip: Insecure calling of polkit

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.

La función check_permission_v1 en base/pkit.py en HP Linux Imaging and Printing (HPLIP) hasta 3.13.9 no usa correctamente D-Bus para comunicaciones con una autoridad polkit, lo cual permite a usuarios locales evitar restricciones de acceso establecidas aprovechando una condición de carrera PolkitUnixProcess PolkitSubject a través de (1) un proceso setuid o (2) un proceso pkexec.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-06-12 CVE Reserved
  • 2013-09-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
1.0
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "1.0"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
2.0
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "2.0"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
2.7.10
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "2.7.10"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.2
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.2"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.4
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.4"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.4b
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.4b"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.6
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.6"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.8
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.8"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.10
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.10"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.9.12
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.9.12"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.10.2
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.10.2"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.10.5
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.10.5"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.10.6
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.10.6"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.10.9
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.10.9"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.11.1
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.11.1"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.11.3
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.11.3"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.11.3a
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.11.3a"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.11.5
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.11.5"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.11.7
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.11.7"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.11.10
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.11.10"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.2
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.2"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.4
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.4"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.6
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.6"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.9
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.9"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.10
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.10"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.10
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.10"
a
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.12.11
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.12.11"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.2
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.2"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.3
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.3"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.4
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.4"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.5
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.5"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.6
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.6"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.7
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.7"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.8
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.8"
-
Affected
Hp
Search vendor "Hp"
Linux Imaging And Printing Project
Search vendor "Hp" for product "Linux Imaging And Printing Project"
3.13.9
Search vendor "Hp" for product "Linux Imaging And Printing Project" and version "3.13.9"
-
Affected