systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1961-1 | vendor advisory |
http://www.openwall.com/lists/oss-security/2013/09/18/6 | third party advisory mailing list |
http://www.debian.org/security/2013/dsa-2777 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1006680 | issue tracking third party advisory patch |