---
cve: "CVE-2013-1061"
severity: "LOW"
cvss: 3.1
epss: "36%"
vendor: "n/a"
kev: false
exploited: false
published: "2013-10-03 21:55:03"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T00:24:24+02:00"
---

# CVE-2013-1061

> 3.1 LOW

## Beschreibung

dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

## Referenzen

- <https://launchpad.net/ubuntu/+source/software-properties/0.82.7.5>
- <http://launchpadlibrarian.net/150156695/software-properties_0.92.17.2_0.92.17.3.diff.gz>
- <https://launchpad.net/ubuntu/+source/software-properties/0.92.17.3>
- <https://launchpad.net/ubuntu/+source/software-properties/0.92.9.3>
- <http://secunia.com/advisories/54909>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/87381>
- <http://www.ubuntu.com/usn/USN-1960-1>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-1061) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
