CVE-2011-2533: Low severity freedesktop d-bus vulnerability
Published Jun 22, 2011
·Updated
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
Affected Software
14 affected components
Freedesktop dbus=1.2.1
Freedesktop dbus=1.2.3
Freedesktop dbus=1.2.4
Freedesktop dbus=1.2.6
Freedesktop dbus=1.2.8
Freedesktop dbus=1.2.10
Freedesktop dbus=1.2.12
Freedesktop dbus=1.2.14
Freedesktop dbus=1.2.16
Freedesktop dbus=1.2.18
Freedesktop dbus=1.2.20
Freedesktop dbus=1.2.22
Freedesktop dbus=1.2.24
Freedesktop dbus=1.2.26
Event History
Jun 22, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2533?
CVE-2011-2533 is considered a medium severity vulnerability due to its potential for local file overwriting.
2
How do I fix CVE-2011-2533?
To fix CVE-2011-2533, upgrade to D-Bus version 1.2.28 or later, where the vulnerability has been addressed.
3
What kind of attack does CVE-2011-2533 enable?
CVE-2011-2533 enables a symlink attack that allows local users to overwrite arbitrary files.
4
Which versions of D-Bus are affected by CVE-2011-2533?
CVE-2011-2533 affects D-Bus versions from 1.2.1 up to, but not including, 1.2.28.
5
What can be the impact of CVE-2011-2533 on a system?
The impact of CVE-2011-2533 on a system includes potential loss of data integrity due to unauthorized file modifications.