{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2013-1060", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently reads the system configuration file from the ~buildd directory, which allows local users to gain privileges by leveraging control over the buildd account." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[kernel-team] 20130731 [CVE-2013-1060] perf configuration file vunerability", "refsource" : "MLIST", "url" : "https://lists.ubuntu.com/archives/kernel-team/2013-July/031248.html" }, { "name" : "[kernel-team] 20130731 [lucid CVE 1/1] UBUNTU: [Packaging] supply perf with appropriate prefix to ensure use of local config", "refsource" : "MLIST", "url" : "https://lists.ubuntu.com/archives/kernel-team/2013-July/031249.html" }, { "name" : "http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-1060.html", "refsource" : "CONFIRM", "url" : "http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-1060.html" }, { "name" : "https://launchpad.net/bugs/1206200", "refsource" : "CONFIRM", "url" : "https://launchpad.net/bugs/1206200" }, { "name" : "USN-1938-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1938-1" }, { "name" : "USN-1939-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1939-1" }, { "name" : "USN-1941-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1941-1" }, { "name" : "USN-1942-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1942-1" }, { "name" : "USN-1943-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1943-1" }, { "name" : "USN-1944-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1944-1" }, { "name" : "USN-1945-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1945-1" }, { "name" : "USN-1946-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1946-1" }, { "name" : "USN-1947-1", "refsource" : "UBUNTU", "url" : "http://www.ubuntu.com/usn/USN-1947-1" } ] } }