CVE-2013-4326 PUBLISHED CVSS 4.599999904632568 MEDIUM

RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

EPSS 0.06% · 19.3th percentile

Risk Scores

CVSS v2.0
4.599999904632568
EPSS Score
0.06%
19.3th percentile

Affected Products

VendorProductVersions
n/an/an/a
redhatenterprise_linux6.0
lennart_poetteringrkit0.5

Timeline

References

Open in Interactive Console →