PT-2012-6365 · Freedesktop.Org+3 · Libdbus-1-3+4

Sebastian Krahmer

·

Publicado

1970-01-01

·

Atualizado

2024-06-15

·

CVE-2012-3524

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dbus versions 1.2.24 through 1.5.x dbus version 1.6.8 and earlier libdbus-1-3 (affected versions not specified) libdbus-1-3-32bit (affected versions not specified) dbus-1 (affected versions not specified) dbus-1-32bit (affected versions not specified) dbus-libs-1.2.24 dbus-devel-1.2.24 dbus-debuginfo-1.2.24 dbus-doc-1.2.24 dbus-x11-1.1.24
Description The issue allows local users to gain privileges and execute arbitrary code via the DBUS SYSTEM BUS ADDRESS environment variable. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the vulnerability can be carried out locally.
Recommendations For dbus versions 1.2.24 through 1.5.x: As a temporary workaround, consider sanitizing the environment variables before the first call into libdbus. For dbus version 1.6.8 and earlier: Update to a version later than 1.6.8. For libdbus-1-3, libdbus-1-3-32bit, dbus-1, dbus-1-32bit: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For dbus-libs-1.2.24, dbus-devel-1.2.24, dbus-debuginfo-1.2.24, dbus-doc-1.2.24, dbus-x11-1.1.24: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-05482
BDU:2015-05483
BDU:2015-05484
BDU:2015-05485
BDU:2015-05486
BDU:2015-05487
BDU:2015-05488
BDU:2015-05489
BDU:2015-05490
BDU:2015-05491
BDU:2015-05492
BDU:2015-05493
BDU:2015-05494
BDU:2015-05495
BDU:2015-05496
BDU:2015-05497
BDU:2015-05498
BDU:2015-06721
BDU:2015-06722
BDU:2015-06725
BDU:2015-06726
BDU:2015-06734
BDU:2015-06737
BDU:2015-08867
BDU:2015-08868
BDU:2015-08869
BDU:2015-08870
BDU:2015-08871
BDU:2015-08872
BDU:2015-09716
CESA-2012_1261
CVE-2012-3524
OPENSUSE-SU-2012_1287-1
OPENSUSE-SU-2024:10473-1
OPENSUSE-SU-2024:10517-1
RHSA-2012:1261
RHSA-2012_1261

Produtos afetados

Centos
Red Hat
Suse
Dbus
Libdbus-1-3