Race condition in libvirt allows local users to bypass access restrictions via PolkitUnixProcess PolkitSubject race condition in pkcheck

Race condition in libvirt allows local users to bypass access restrictions via PolkitUnixProcess PolkitSubject race condition in pkcheck

CVE-2013-4311 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Learn more about our User Device Pen Test.