VDB

DEBIAN-CVE-2013-4288

DEBIAN-CVE-2013-4288 PUBLISHED

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

Affected Products

VendorProductVersions
Debian:14policykit-10, 0, 0
Debian:13policykit-10, 0, 0
Debian:12policykit-10, 0, 0
Debian:11policykit-10, 0, 0

Timeline

  • Oct 3, 2013 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›