PT-2019-3286 · Freedesktop.Org+5 · Dbus Cookie Sha1+9

Joe Vennix

·

Publicado

2019-05-28

·

Atualizado

2026-02-13

·

CVE-2019-12749

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions dbus versions 1.10.28 and earlier, 1.12.x prior to 1.12.16, and 1.13.x prior to 1.13.12
Description The issue is related to the DBUS COOKIE SHA1 authentication mechanism in the libdbus library, which is used in DBusServer in Canonical Upstart in Ubuntu 14.04. A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. This could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.
Recommendations For dbus versions 1.10.28 and earlier, update to version 1.10.28 or later. For dbus 1.12.x prior to 1.12.16, update to version 1.12.16 or later. For dbus 1.13.x prior to 1.13.12, update to version 1.13.12 or later. As a temporary workaround, consider restricting access to the ~/.dbus-keyrings directory to prevent symlink manipulation.

Correção

Link Following

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-3092
ALT-PU-2019-3127
AZL-6371
BDU:2019-03326
CESA-2019_1726
CESA-2019_3707
CESA-2020_4032
CVE-2019-12749
DLA-1818-1
DSA-4462-1
MGASA-2019-0339
OPENSUSE-SU-2019:1604-1
OPENSUSE-SU-2019:1671-1
OPENSUSE-SU-2019:1750-1
OPENSUSE-SU-2019_1604-1
OPENSUSE-SU-2019_1671-1
OPENSUSE-SU-2019_1750-1
OPENSUSE-SU-2024:10711-1
RHSA-2019:1726
RHSA-2019:2868
RHSA-2019:2870
RHSA-2019:3707
RHSA-2019_1726
RHSA-2019_3707
RHSA-2020:4032
RHSA-2020_4032
SUSE-SU-2019:14111-1
SUSE-SU-2019:1521-1
SUSE-SU-2019:1591-1
SUSE-SU-2019:1595-1
SUSE-SU-2019:1597-1
SUSE-SU-2019:2820-2
SUSE-SU-2019_14111-1
SUSE-SU-2019_1521-1
SUSE-SU-2019_1591-1
SUSE-SU-2019_1595-1
SUSE-SU-2019_1597-1
SUSE-SU-2019_2820-1
SUSE-SU-2019_2820-2
SUSE-SU-2020:1672-1
SUSE-SU-2020_1672-1
USN-4015-1
USN-4015-2

Produtos afetados

Alt Linux
Centos
Dbus Cookie Sha1
Dbusserver
Red Hat
Suse
Ubuntu
Upstart
Dbus
Libdbus