CVE-2010-1172

Publication date 20 August 2010

Last updated 24 July 2024


Ubuntu priority

DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.

Read the notes from the security team

Status

Package Ubuntu Release Status
dbus-glib 11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Fixed 0.84-1ubuntu0.2
9.10 karmic Ignored end of life
9.04 jaunty Ignored end of life
8.04 LTS hardy
Fixed 0.74-2ubuntu0.1
6.06 LTS dapper Not in release

Notes


jdstrand

network-manager and modemmanager require a no change rebuild to incorporate the changes

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
dbus-glib

References

Related Ubuntu Security Notices (USN)

Other references