CVE-2013-1066

Publication date 18 September 2013

Last updated 24 July 2024


Ubuntu priority

language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Status

Package Ubuntu Release Status
language-selector 13.04 raring
Fixed 0.110.1
12.10 quantal
Fixed 0.90.1
12.04 LTS precise
Fixed 0.79.4
10.04 LTS lucid
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-1958-1
    • language-selector vulnerability
    • 18 September 2013

Other references