~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2013-4311

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2013-09-18
2
 
Candidate: CVE-2013-4311
3
 
PublicDate: 2013-10-03
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4311
6
 
 https://usn.ubuntu.com/usn/usn-1954-1
7
 
Description:
8
 
 libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x
9
 
 before 0.9.12.2 allows local users to bypass intended access restrictions
10
 
 by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck
11
 
 via a (1) setuid process or (2) pkexec process, a related issue to
12
 
 CVE-2013-4288.
13
 
Ubuntu-Description: 
14
 
Notes: 
15
 
Bugs: 
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to: 
19
 
 
20
 
Patches_libvirt:
21
 
 upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=db7a5688c05f3fd60d9d2b74c72427eb9ee9c176
22
 
 upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=e65667c0c6e016d42abea077e31628ae43f57b74
23
 
 upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=922b7fda77b094dbf022d625238262ea05335666
24
 
 upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=e4697b92abaad16e8e6b41a1e55be9b084d48d5a (fix)
25
 
upstream_libvirt: needs-triage
26
 
lucid_libvirt: released (0.7.5-5ubuntu27.24)
27
 
precise_libvirt: released (0.9.8-2ubuntu17.13)
28
 
quantal_libvirt: released (0.9.13-0ubuntu12.5)
29
 
raring_libvirt: released (1.0.2-0ubuntu11.13.04.4)
30
 
devel_libvirt: released (1.1.1-0ubuntu6)