CVE-2009-0489: Low severity David Paleino Wicd vulnerability
The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WICDto a version that resolves this vulnerability.Fixed in 1.5.9
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0489?
CVE-2009-0489 is classified as a medium severity vulnerability due to potential unauthorized access to sensitive messages.
How do I fix CVE-2009-0489?
To fix CVE-2009-0489, upgrade Wicd to version 1.5.9 or later where the DBus configuration has been secured.
What are the affected versions in CVE-2009-0489?
CVE-2009-0489 affects Wicd versions prior to 1.5.9, specifically versions 1.2.7 through 1.5.8.
What type of vulnerability is CVE-2009-0489?
CVE-2009-0489 is a local privilege escalation vulnerability that allows unauthorized users to interact with the Wicd daemon.
What can be compromised due to CVE-2009-0489?
Due to CVE-2009-0489, local users may potentially receive messages intended for the Wicd daemon, including sensitive credential information.