← Back

CVE-2013-4325

nvd nist
Published: Sep 23, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD

Description

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.

Affected (35)

1 product
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Hp
Version 1.0
Version 2.0
Version 2.7.10
Version 3.10.2
Version 3.10.5
Version 3.10.6
Version 3.10.9
Version 3.11.10
Version 3.11.1
Version 3.11.3
Version 3.11.3a
Version 3.11.5
Version 3.11.7
Version 3.12.10
Version 3.12.10 a
Version 3.12.11
Version 3.12.2
Version 3.12.4
Version 3.12.6
Version 3.12.9
Version 3.13.2
Version 3.13.3
Version 3.13.4
Version 3.13.5
Version 3.13.6
Version 3.13.7
Version 3.13.8
Version 3.13.9
Version 3.9.10
Version 3.9.12
Version 3.9.2
Version 3.9.4
Version 3.9.4b
Version 3.9.6
Version 3.9.8

Related CWEs

References (14)

Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.