CVE-2013-4324 PUBLISHED CVSS 4.599999904632568 MEDIUM

spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

EPSS 0.07% · 20.0th percentile

Risk Scores

CVSS v2.0
4.599999904632568
EPSS Score
0.07%
20.0th percentile

Affected Products

VendorProductVersions
spice-gtk_projectspice-gtk0.14
redhatenterprise_linux6.0
n/an/an/a

Timeline

References

Open in Interactive Console →