VulnerabilityModified
CVE-2009-0489
The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.
LOW 2.1EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- david paleino/wicd
- Source
- cve@mitre.org
References
- http://bazaar.launchpad.net/~wicd-devel/wicd/trunk/revision/222
- http://secunia.com/advisories/33870
- http://secunia.com/advisories/34685
- http://security.gentoo.org/glsa/glsa-200904-12.xml
- http://sourceforge.net/project/shownotes.php?group_id=194573&release_id=659059
- http://www.openwall.com/lists/oss-security/2009/02/06/4
- http://bazaar.launchpad.net/~wicd-devel/wicd/trunk/revision/222
- http://secunia.com/advisories/33870
- http://secunia.com/advisories/34685
- http://security.gentoo.org/glsa/glsa-200904-12.xml
- http://sourceforge.net/project/shownotes.php?group_id=194573&release_id=659059
- http://www.openwall.com/lists/oss-security/2009/02/06/4
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.