CVE-2013-4325: HP Linux Imaging And Printing Project
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.
Affected products
- HP Linux Imaging And Printing Project: version 1.0 only; version 2.0 only; version 2.7.10 only; version 3.9.2 only; version 3.9.4 only; version 3.9.4b only; …
Published 2013-09-23. Last modified 2026-06-16.