---
cve: "CVE-2013-1066"
severity: "LOW"
cvss: 3.1
epss: "38%"
vendor: "n/a"
kev: false
exploited: false
published: "2013-10-03 21:55:03"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-14T11:27:25+02:00"
---

# CVE-2013-1066

> 3.1 LOW

## Beschreibung

language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

## Referenzen

- <https://launchpad.net/ubuntu/+source/language-selector/0.90.1>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/87379>
- <https://launchpad.net/ubuntu/+source/language-selector/0.110.1>
- <http://www.ubuntu.com/usn/USN-1958-1>
- <https://launchpad.net/ubuntu/+source/language-selector/0.79.4>
- <http://secunia.com/advisories/54911>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-1066) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
