Canonical

Ubuntu Linux

4107 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new A...

  • EPSS 0.02%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...

  • EPSS 0.03%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec proce...

  • EPSS 0.06%
  • Veröffentlicht 03.10.2013 21:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended acce...

  • EPSS 0.05%
  • Veröffentlicht 03.10.2013 21:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

ubuntu-system-service 0.2.4 before 0.2.4.1. 0.2.3 before 0.2.3.1, and 0.2.2 before 0.2.2.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUn...

  • EPSS 0.06%
  • Veröffentlicht 03.10.2013 21:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitU...

  • EPSS 0.06%
  • Veröffentlicht 03.10.2013 21:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

apt-xapian-index before 0.45ubuntu2.1, 0.44ubuntu7.1, and 0.44ubuntu5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSub...

  • EPSS 0.06%
  • Veröffentlicht 03.10.2013 21:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a ...

  • EPSS 0.06%
  • Veröffentlicht 03.10.2013 21:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnix...

  • EPSS 18.73%
  • Veröffentlicht 01.10.2013 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authenticatio...