Description
backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1957-1
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/54912
Patch x_refsource_confirm
https://launchpad.net/ubuntu/+source/jockey/0.9.7-0ubuntu7.11
Scores
EPSS
0.0037
EPSS Percentile
29.7%
Details
CWE
CWE-264
Status
published
Products (12)
canonical/ubuntu_linux
12.04
martin_pitt/jockey
0.9.7-0ubuntu7
martin_pitt/jockey
0.9.7-0ubuntu7.1
martin_pitt/jockey
0.9.7-0ubuntu7.2
martin_pitt/jockey
0.9.7-0ubuntu7.3
martin_pitt/jockey
0.9.7-0ubuntu7.4
martin_pitt/jockey
0.9.7-0ubuntu7.5
martin_pitt/jockey
0.9.7-0ubuntu7.6
martin_pitt/jockey
0.9.7-0ubuntu7.7
martin_pitt/jockey
0.9.7-0ubuntu7.8
... and 2 more
Published
Oct 03, 2013
Tracked Since
Feb 18, 2026