VDB
CVE-2013-4325
CVE-2013-4325
PUBLISHED
CVSS 6.900000095367432 MEDIUM
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.
EPSS 0.07% · 20.3th percentile
Risk Scores
CVSS 2.0
6.900000095367432
EPSS Score
0.07%
20.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| hp | linux_imaging_and_printing_project | 2.0, 2.7.10, 3.9.2 |
Exploit Intelligence
- RHSA-2013:1274 (circl)
- USN-1956-1 (circl)
- openSUSE-SU-2013:1617 (circl)
- https://bugzilla.redhat.com/show_bug.cgi?id=1002375 (circl)
- DSA-2829 (circl)
- openSUSE-SU-2013:1620 (circl)
- https://bugzilla.redhat.com/show_bug.cgi?id=1006674 (circl)
Timeline
- Sep 23, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- RHSA-2013:1274 vendor-advisory
- USN-1956-1 vendor-advisory
- openSUSE-SU-2013:1617 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1002375 url
- DSA-2829 vendor-advisory
- openSUSE-SU-2013:1620 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1006674 url
- https://nvd.nist.gov/vuln/detail/CVE-2013-4325 advisory