PT-2013-1182 · Red Hat+1 · Spice-Gtk+9

Sebastian Krahmer

·

Published

2013-09-19

·

Updated

2019-06-17

·

CVE-2013-4324

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions spice-gtk versions 0.14 spice-gtk-python versions 0.14 spice-glib versions 0.14 spice-glib-devel versions 0.14 spice-gtk-devel versions 0.14 spice-gtk-debuginfo versions 0.14 spice-gtk-tools versions 0.14
Description The issue allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process. This can lead to a violation of confidentiality, integrity, and availability of protected information. The polkit unix process new API function is used insecurely, contributing to the vulnerability.
Recommendations For spice-gtk version 0.14, consider disabling the polkit unix process new function until a patch is available. For spice-gtk-python version 0.14, restrict access to the polkit unix process new function to minimize the risk of exploitation. For spice-glib version 0.14, avoid using the polkit unix process new function in sensitive operations until the issue is resolved. For spice-glib-devel version 0.14, consider applying configuration changes to limit the impact of the vulnerability. For spice-gtk-devel version 0.14, restrict access to the vulnerable module to minimize the risk of exploitation. For spice-gtk-debuginfo version 0.14, consider disabling the polkit unix process new function until a patch is available. For spice-gtk-tools version 0.14, avoid using the polkit unix process new function in sensitive operations until the issue is resolved.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06916
BDU:2015-06918
BDU:2015-06920
BDU:2015-06922
BDU:2015-06924
BDU:2015-06926
BDU:2015-06928
BDU:2015-09043
BDU:2015-09044
BDU:2015-09045
BDU:2015-09046
BDU:2015-09047
BDU:2015-09744
CESA-2013_1273
CVE-2013-4324
MGASA-2013-0293
RHSA-2013:1273
RHSA-2013_1273

Affected Products

Centos
Polkit
Red Hat
Spice-Glib
Spice-Glib-Devel
Spice-Gtk
Spice-Gtk-Debuginfo
Spice-Gtk-Devel
Spice-Gtk-Python
Spice-Gtk-Tools