---
title: "CVE-2012-3524\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-3524?format=md
keywords: index, follow
---

# CVE-2012-3524

Publication date 14 September 2012

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

libdbus 1.5.x and earlier, when used in setuid or other privileged programs
in X.org and possibly other products, allows local users to gain privileges
and execute arbitrary code via the DBUS\_SYSTEM\_BUS\_ADDRESS environment
variable. NOTE: libdbus maintainers state that this is a vulnerability in
the applications that do not cleanse environment variables, not in libdbus
itself: "we do not support use of libdbus in setuid binaries that do not
sanitize their environment before their first call into libdbus."

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| dbus | 12.04 LTS precise | Fixed 1.4.18-1ubuntu1.1 |
| 11.10 oneiric | Fixed 1.4.14-1ubuntu1.1 |
| 11.04 natty | Fixed 1.4.6-1ubuntu6.2 |
| 10.04 LTS lucid | Fixed 1.2.16-2ubuntu4.5 |
| 8.04 LTS hardy | Fixed 1.1.20-1ubuntu3.7 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3524)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-3524)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-3524)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-3524)

### Related Ubuntu Security Notices (USN)

+ [USN-1576-1](https://usn.ubuntu.com/USN-1576-1)
+ DBus vulnerability
+ 20 September 2012

+ [USN-1576-2](https://usn.ubuntu.com/USN-1576-2)
+ DBus regressions
+ 4 October 2012

### Other references

* <http://stealth.openwall.net/null/dzug.c>
* <https://rhn.redhat.com/errata/RHSA-2012-1261.html>
* <http://seclists.org/oss-sec/2012/q3/439>
* <https://www.cve.org/CVERecord?id=CVE-2012-3524>
