PT-2008-6962 · Gpomme+7 · Gpomme+14

Colin Walters

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2008-4311

CVSS v2.0

6.2

Média

VetorAV:L/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions dbus-1-glib versions prior to 1.2.6 hal versions prior to 1.2.6 bluez versions prior to 1.2.6 PolicyKit versions prior to 1.2.6 powersave versions prior to 1.2.6 dbus-1-python versions prior to 1.2.6 dbus-1-qt3 versions prior to 1.2.6 dbus-1-mono versions prior to 1.2.6 dbus-1-gtk versions prior to 1.2.6 dbus-1-x11 versions prior to 1.2.6 pommed versions prior to 1.2.6 gpomme versions prior to 1.2.6 wmpomme versions prior to 1.2.6 PackageKit versions prior to 1.2.6 libbluetooth3 versions prior to 1.2.6
Description The vulnerability allows local attackers to bypass intended access restrictions by sending or receiving messages. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerability can be carried out locally by an attacker who has passed the authentication procedure.
Recommendations As a temporary workaround, consider disabling the send type attribute in the system.conf file of D-Bus until a patch is available. Restrict access to the vulnerable packages to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. Update the affected packages to a version later than 1.2.6. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04660
BDU:2015-04661
BDU:2015-04662
BDU:2015-04663
BDU:2015-04664
BDU:2015-04665
BDU:2015-04666
BDU:2015-04667
BDU:2015-04668
BDU:2015-04669
BDU:2015-04670
BDU:2015-04671
BDU:2015-04672
BDU:2015-04673
BDU:2015-04674
BDU:2015-04675
BDU:2015-04676
BDU:2015-04677
BDU:2015-04678
BDU:2015-04679
BDU:2015-04680
BDU:2015-04681
BDU:2015-04682
BDU:2015-04683
BDU:2015-04684
BDU:2015-04685
BDU:2015-04686
BDU:2015-04687
BDU:2015-04688
BDU:2015-04689
BDU:2015-04690
BDU:2015-04691
BDU:2015-04692
BDU:2015-04693
BDU:2015-04694
BDU:2015-04695
BDU:2015-04696
BDU:2015-04697
BDU:2015-04698
BDU:2015-04699
BDU:2015-04700
BDU:2015-04701
BDU:2015-04702
BDU:2015-04703
BDU:2015-04704
BDU:2015-04705
BDU:2015-04706
BDU:2015-04707
BDU:2015-04708
BDU:2015-04709
BDU:2015-04710
BDU:2015-04711
BDU:2015-04712
BDU:2015-04713
BDU:2015-04714
BDU:2015-04715
BDU:2015-04716
BDU:2015-04717
BDU:2015-04718
BDU:2015-04719
BDU:2015-04720
BDU:2015-04721
BDU:2015-04722
BDU:2015-05036
BDU:2015-05037
BDU:2015-05038
BDU:2015-05039
BDU:2015-05040
BDU:2015-05041
BDU:2015-05042
BDU:2015-05043
BDU:2015-05044
BDU:2015-05045
BDU:2015-05046
BDU:2015-05047
BDU:2015-05048
BDU:2015-05049
BDU:2015-05050
BDU:2015-05051
BDU:2015-05052
BDU:2015-05053
BDU:2015-05054
BDU:2015-05055
BDU:2015-05056
BDU:2015-05057
BDU:2015-05058
BDU:2015-05059
BDU:2015-05060
BDU:2015-05061
BDU:2015-05062
BDU:2015-05063
BDU:2015-05064
BDU:2015-05065
BDU:2015-05066
BDU:2015-05067
BDU:2015-05068
BDU:2015-05069
BDU:2015-05070
BDU:2015-05071
BDU:2015-05072
BDU:2015-05073
BDU:2015-05074
BDU:2015-05075
BDU:2015-05076
BDU:2015-05077
BDU:2015-05078
BDU:2015-05079
BDU:2015-05080
BDU:2015-05081
BDU:2015-05082
BDU:2015-05083
BDU:2015-05084
BDU:2015-05085
BDU:2015-05086
BDU:2015-05087
BDU:2015-05088
BDU:2015-05089
BDU:2015-05090
BDU:2015-05091
BDU:2015-05092
BDU:2015-05093
BDU:2015-05094
BDU:2015-05095
BDU:2015-05096
BDU:2015-05097
BDU:2015-05098
BDU:2015-05099
BDU:2015-05100
BDU:2015-05101
BDU:2015-05102
BDU:2015-05103
BDU:2015-05104
CVE-2008-4311
OPENSUSE-SU-2024:10605-1
OPENSUSE-SU-2024:10711-1
OPENSUSE-SU-2024:11531-1

Produtos afetados

Packagekit
Policykit
Bluez
Dbus-1-Glib
Dbus-1-Gtk
Dbus-1-Mono
Dbus-1-Python
Dbus-1-Qt3
Dbus-1-X11
Gpomme
Hal
Libbluetooth3
Pommed
Powersave
Wmpomme