VDB
CVE-2013-4325
CVE-2013-4325
PUBLISHED
CVSS 6.900000095367432 MEDIUM
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.
EPSS 0.42% · 34.6th percentile
Risk Scores
CVSS 2.0
6.900000095367432
EPSS Score
0.42%
34.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| hp | linux_imaging_and_printing_project | 2.0, 2.7.10, 3.9.2 |
Timeline
- Sep 23, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- RHSA-2013:1274 vendor-advisory
- USN-1956-1 vendor-advisory
- DSA-2829 vendor-advisory
- openSUSE-SU-2013:1617 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1002375 url
- openSUSE-SU-2013:1620 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1006674 url
- https://nvd.nist.gov/vuln/detail/CVE-2013-4325 advisory