[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-3524Date: (C)2012-09-18   (M)2023-12-22


libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
EXPLOIT-DB-21323
SECUNIA-50537
SECUNIA-50544
SECUNIA-50710
BID-55517
MDVSA-2013:070
MDVSA-2013:083
RHSA-2012:1261
SUSE-SU-2012:1155
SUSE-SU-2012:1155-2
USN-1576-1
USN-1576-2
http://www.openwall.com/lists/oss-security/2012/07/10/4
http://www.openwall.com/lists/oss-security/2012/07/26/1
http://www.openwall.com/lists/oss-security/2012/09/12/6
http://www.openwall.com/lists/oss-security/2012/09/14/2
http://www.openwall.com/lists/oss-security/2012/09/17/2
http://stealth.openwall.net/null/dzug.c
https://bugs.freedesktop.org/show_bug.cgi?id=52202
https://bugzilla.novell.com/show_bug.cgi?id=697105
https://bugzilla.redhat.com/show_bug.cgi?id=847402
openSUSE-SU-2012:1287
openSUSE-SU-2012:1418

CPE    7
cpe:/a:freedesktop:libdbus
cpe:/a:freedesktop:libdbus:1.5.8
cpe:/a:freedesktop:libdbus:1.5.6
cpe:/a:freedesktop:libdbus:1.5.10
...
CWE    1
CWE-264
OVAL    10
oval:org.secpod.oval:def:400415
oval:org.secpod.oval:def:701029
oval:org.secpod.oval:def:701007
oval:org.secpod.oval:def:202448
...

© SecPod Technologies