CVE-2008-0595
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a…
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- fedoraproject/fedora · mandrakesoft/mandrake linux · redhat/enterprise linux · freedesktop/dbus
- Source
- secalert@redhat.com
References
- http://lists.freedesktop.org/archives/dbus/2008-February/009401.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlThird Party Advisory
- http://secunia.com/advisories/29148Broken Link
- http://secunia.com/advisories/29160Broken Link
- http://secunia.com/advisories/29171Broken Link
- http://secunia.com/advisories/29173Broken Link
- http://secunia.com/advisories/29281Broken Link
- http://secunia.com/advisories/29323Broken Link
- http://secunia.com/advisories/30869Broken Link
- http://secunia.com/advisories/32281Broken Link
- http://securitytracker.com/id?1019512Third Party Advisory, VDB Entry
- http://wiki.rpath.com/Advisories:rPSA-2008-0099Third Party Advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0099Third Party Advisory
- http://www.debian.org/security/2008/dsa-1599Third Party Advisory
- http://www.j5live.com/2008/02/27/announce-d-bus-1120-conisten-water-released/Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:054Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0159.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/489280/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28023Patch, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-653-1Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0694Broken Link
- https://issues.rpath.com/browse/RPL-2282Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9353Broken Link
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00893.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00911.htmlThird Party Advisory
- http://lists.freedesktop.org/archives/dbus/2008-February/009401.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlThird Party Advisory
- http://secunia.com/advisories/29148Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.