First published: Mon Mar 04 2013(Updated: )
The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
freedesktop dbus-glib | <=0.100 | |
freedesktop dbus-glib | =0.72 | |
freedesktop dbus-glib | =0.73 | |
freedesktop dbus-glib | =0.74 | |
freedesktop dbus-glib | =0.76 | |
freedesktop dbus-glib | =0.78 | |
freedesktop dbus-glib | =0.80 | |
freedesktop dbus-glib | =0.82 | |
freedesktop dbus-glib | =0.84 | |
freedesktop dbus-glib | =0.86 | |
freedesktop dbus-glib | =0.88 | |
freedesktop dbus-glib | =0.90 | |
freedesktop dbus-glib | =0.92 | |
freedesktop dbus-glib | =0.94 | |
freedesktop dbus-glib | =0.96 | |
freedesktop dbus-glib | =0.98 |
http://cgit.freedesktop.org/dbus/dbus-glib/commit/?id=166978a09cf5edff4028e670b6074215a4c75eca
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.