CVE-2012-3524
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.
Does this matter?
Lower severity and a low EPSS score (4.48%). Track it; it rarely justifies an emergency change on its own.
Description
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.48% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- freedesktop/libdbus
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
- http://rhn.redhat.com/errata/RHSA-2012-1261.html
- http://secunia.com/advisories/50537Vendor Advisory
- http://secunia.com/advisories/50544
- http://secunia.com/advisories/50710
- http://stealth.openwall.net/null/dzug.cExploit
- http://www.exploit-db.com/exploits/21323Exploit
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:070
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:083
- http://www.openwall.com/lists/oss-security/2012/07/10/4
- http://www.openwall.com/lists/oss-security/2012/07/26/1
- http://www.openwall.com/lists/oss-security/2012/09/12/6
- http://www.openwall.com/lists/oss-security/2012/09/14/2
- http://www.openwall.com/lists/oss-security/2012/09/17/2
- http://www.securityfocus.com/bid/55517Exploit
- http://www.ubuntu.com/usn/USN-1576-1
- http://www.ubuntu.com/usn/USN-1576-2
- https://bugs.freedesktop.org/show_bug.cgi?id=52202Patch
- https://bugzilla.novell.com/show_bug.cgi?id=697105
- https://bugzilla.redhat.com/show_bug.cgi?id=847402
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00009.html
- http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00000.html
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00094.html
- http://rhn.redhat.com/errata/RHSA-2012-1261.html
- http://secunia.com/advisories/50537Vendor Advisory
- http://secunia.com/advisories/50544
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.