CVE-2013-4325

Publication date 18 September 2013

Last updated 24 July 2024


Ubuntu priority

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.

Status

Package Ubuntu Release Status
hplip 13.04 raring
Fixed 3.13.3-1ubuntu0.1
12.10 quantal
Fixed 3.12.6-3ubuntu4.1
12.04 LTS precise
Fixed 3.12.2-1ubuntu3.2
10.04 LTS lucid
Fixed 3.10.2-2ubuntu2.3

References

Related Ubuntu Security Notices (USN)

    • USN-1956-1
    • HPLIP vulnerability
    • 18 September 2013

Other references