Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2008-0595

Published: 29 February 2008

dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.

Notes

AuthorNote
jdstrand
be sure to check the redhat bug for test cases

Priority

Medium

Status

Package Release Status
dbus
Launchpad, Ubuntu, Debian
dapper
Released (0.60-6ubuntu8.3)
edgy Ignored
(end of life)
feisty
Released (1.0.2-1ubuntu4.2)
gutsy
Released (1.1.1-3ubuntu4.2)
hardy
Released (1.1.20-1ubuntu1)
upstream Needs triage

Patches:
vendor: https://rhn.redhat.com/errata/RHSA-2008-0159.html
vendor: http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:054