Oval Definition:oval:com.ubuntu.xenial:def:201343240000000
Revision Date:2013-10-03Version:1
Title:CVE-2013-4324 on Ubuntu 16.04 LTS (xenial) - medium.
Description:spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2013-4324
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND spice-gtk package in xenial, is related to the CVE in some way and has been fixed (note: '0.22-0nocent2').
  • BACK