CVE-2008-4311: Medium severity freedesktop d-bus vulnerability
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the sendtype attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to sendrequestedreply; and possibly (2) receiving messages, related to receiverequestedreply.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4311?
CVE-2008-4311 is classified as a moderate severity vulnerability due to its potential to allow local users to bypass access restrictions.
How do I fix CVE-2008-4311?
To fix CVE-2008-4311, upgrade D-Bus to version 1.2.6 or later where the issue has been addressed.
Who is affected by CVE-2008-4311?
CVE-2008-4311 affects all versions of D-Bus prior to 1.2.6.
What type of vulnerability is CVE-2008-4311?
CVE-2008-4311 is a local privilege escalation vulnerability stemming from improper access controls.
Can CVE-2008-4311 affect remote users?
No, CVE-2008-4311 can only be exploited by local users on the affected system.