Vulnerability Database

313,359

Total vulnerabilities in the database

CVE-2013-1065

backend.py in Jockey before 0.9.7-0ubuntu7.11 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

  • Published: Oct 3, 2013
  • Updated: Nov 9, 2025
  • CVE: CVE-2013-1065
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.6
  • AV:L/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
martin_pitt / jockey 0.9.7-0ubuntu7.1 0.9.7-0ubuntu7.1.x
martin_pitt / jockey 0.9.7-0ubuntu7.6 0.9.7-0ubuntu7.6.x
martin_pitt / jockey 0.9.7-0ubuntu7.8 0.9.7-0ubuntu7.8.x
martin_pitt / jockey 0.9.7-0ubuntu7.9 0.9.7-0ubuntu7.9.x
martin_pitt / jockey - 0.9.7-0ubuntu7.10.x
martin_pitt / jockey 0.9.7-0ubuntu7.2 0.9.7-0ubuntu7.2.x
martin_pitt / jockey 0.9.7-0ubuntu7.5 0.9.7-0ubuntu7.5.x
martin_pitt / jockey 0.9.7-0ubuntu7.3 0.9.7-0ubuntu7.3.x
martin_pitt / jockey 0.9.7-0ubuntu7.4 0.9.7-0ubuntu7.4.x
martin_pitt / jockey 0.9.7-0ubuntu7 0.9.7-0ubuntu7.x
martin_pitt / jockey 0.9.7-0ubuntu7.7 0.9.7-0ubuntu7.7.x
canonical / ubuntu_linux 12.04 12.04.x