PT-2011-1153 · Freedesktop.Org · D-Bus
Publicado
2011-06-22
·
Atualizado
2017-08-29
·
CVE-2011-2533
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Bus versions prior to 1.4.12
D-Bus versions 1.2.x before 1.2.28
Description
The issue concerns multiple vulnerabilities in the D-Bus package, which can be exploited locally to compromise the confidentiality, integrity, and availability of protected information. A specific vulnerability in the configure script allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
Recommendations
For D-Bus versions prior to 1.4.12, update to version 1.4.12 or later.
For D-Bus versions 1.2.x before 1.2.28, update to version 1.2.28 or later.
As a temporary workaround, consider restricting access to the configure script to minimize the risk of exploitation.
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
D-Bus