D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another users per-user session bus via that socket.
Name | Vendor | Start Version | End Version |
---|---|---|---|
D-bus | D-bus | * | 0.22 (including) |
Red Hat Enterprise Linux 4 | RedHat | dbus-0:0.22-12.EL.2 | * |
Dbus | Ubuntu | dapper | * |
Dbus | Ubuntu | devel | * |
Dbus | Ubuntu | edgy | * |
Dbus | Ubuntu | feisty | * |
Dbus-glib | Ubuntu | devel | * |
Dbus-glib | Ubuntu | edgy | * |
Dbus-glib | Ubuntu | feisty | * |
Dbus-python | Ubuntu | devel | * |
Dbus-python | Ubuntu | edgy | * |
Dbus-python | Ubuntu | feisty | * |
Dbus-qt3 | Ubuntu | devel | * |
Dbus-qt3 | Ubuntu | edgy | * |
Dbus-qt3 | Ubuntu | feisty | * |
Dbus-sharp | Ubuntu | edgy | * |