D-BUS Session Bus Local Privilege Escalation Vulnerability
BID:12435
Info
D-BUS Session Bus Local Privilege Escalation Vulnerability
| Bugtraq ID: | 12435 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-0201 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 03 2005 12:00AM |
| Updated: | Mar 06 2007 09:55PM |
| Credit: | Daniel Reed <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 D-BUS Inter-Process Communication System 0.23 D-BUS Inter-Process Communication System 0.22 D-BUS Inter-Process Communication System 0.21 D-BUS Inter-Process Communication System 0.20 D-BUS Inter-Process Communication System 0.13 |
| Not Vulnerable: | |
Discussion
D-BUS Session Bus Local Privilege Escalation Vulnerability
A local privilege-escalation vulnerability affects D-BUS because it fails to properly secure message-bus sessions.
An attacker may leverage this issue to send messages to the message bus of an unsuspecting user. This may facilitate command execution with the privileges of the unsuspecting user, ultimately leading to privilege escalation.
A local privilege-escalation vulnerability affects D-BUS because it fails to properly secure message-bus sessions.
An attacker may leverage this issue to send messages to the message bus of an unsuspecting user. This may facilitate command execution with the privileges of the unsuspecting user, ultimately leading to privilege escalation.
Exploit / POC
D-BUS Session Bus Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
D-BUS Session Bus Local Privilege Escalation Vulnerability
Solution:
The vendor has updated the CVS version of the affected software. A source patch is also available. Please see the references for more information.
D-BUS Inter-Process Communication System 0.22
Solution:
The vendor has updated the CVS version of the affected software. A source patch is also available. Please see the references for more information.
D-BUS Inter-Process Communication System 0.22
-
Fedora dbus-0.22-10.FC3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-0.22-10.FC3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-debuginfo-0.22-10.FC3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-debuginfo-0.22-10.FC3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-devel-0.22-10.FC3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-devel-0.22-10.FC3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-glib-0.22-10.FC3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-glib-0.22-10.FC3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-python-0.22-10.FC3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-python-0.22-10.FC3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-x11-0.22-10.FC3.2.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora dbus-x11-0.22-10.FC3.2.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Ubuntu dbus-1-dev_0.22-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-dev_0.22-1ub untu2.1_amd64.deb -
Ubuntu dbus-1-dev_0.22-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-dev_0.22-1ub untu2.1_i386.deb -
Ubuntu dbus-1-dev_0.22-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-dev_0.22-1ub untu2.1_powerpc.deb -
Ubuntu dbus-1-utils_0.22-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-utils_0.22-1 ubuntu2.1_amd64.deb -
Ubuntu dbus-1-utils_0.22-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-utils_0.22-1 ubuntu2.1_i386.deb -
Ubuntu dbus-1-utils_0.22-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-utils_0.22-1 ubuntu2.1_powerpc.deb -
Ubuntu dbus-1_0.22-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1_0.22-1ubuntu 2.1_amd64.deb -
Ubuntu dbus-1_0.22-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1_0.22-1ubuntu 2.1_i386.deb -
Ubuntu dbus-1_0.22-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1_0.22-1ubuntu 2.1_powerpc.deb -
Ubuntu dbus-glib-1-dev_0.22-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-glib-1-dev_0.2 2-1ubuntu2.1_amd64.deb -
Ubuntu dbus-glib-1-dev_0.22-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-glib-1-dev_0.2 2-1ubuntu2.1_i386.deb -
Ubuntu dbus-glib-1-dev_0.22-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-glib-1-dev_0.2 2-1ubuntu2.1_powerpc.deb -
Ubuntu dbus-glib-1_0.22-1ubuntu2.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-glib-1_0.22-1u buntu2.1_amd64.deb -
Ubuntu dbus-glib-1_0.22-1ubuntu2.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-glib-1_0.22-1u buntu2.1_i386.deb -
Ubuntu dbus-glib-1_0.22-1ubuntu2.1_powerpc.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-glib-1_0.22-1u buntu2.1_powerpc.deb -
Ubuntu dbus/dbus-1-doc_0.22-1ubuntu2.1_all.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/d/dbus/dbus-1-doc_0.22-1ub untu2.1_all.deb
References
D-BUS Session Bus Local Privilege Escalation Vulnerability
References:
References: