CVE Vulnerabilities

CVE-2008-4311

Published: Dec 10, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.

Affected Software

NameVendorStart VersionEnd Version
DbusFreedesktop*1.2.4 (including)
DbusFreedesktop0.1 (including)0.1 (including)
DbusFreedesktop0.2 (including)0.2 (including)
DbusFreedesktop0.3 (including)0.3 (including)
DbusFreedesktop0.4 (including)0.4 (including)
DbusFreedesktop0.5 (including)0.5 (including)
DbusFreedesktop0.6 (including)0.6 (including)
DbusFreedesktop0.7 (including)0.7 (including)
DbusFreedesktop0.8 (including)0.8 (including)
DbusFreedesktop0.9 (including)0.9 (including)
DbusFreedesktop0.10 (including)0.10 (including)
DbusFreedesktop0.11 (including)0.11 (including)
DbusFreedesktop0.12 (including)0.12 (including)
DbusFreedesktop0.13 (including)0.13 (including)
DbusFreedesktop0.20 (including)0.20 (including)
DbusFreedesktop0.21 (including)0.21 (including)
DbusFreedesktop0.22 (including)0.22 (including)
DbusFreedesktop0.23 (including)0.23 (including)
DbusFreedesktop0.23.1 (including)0.23.1 (including)
DbusFreedesktop0.23.2 (including)0.23.2 (including)
DbusFreedesktop0.23.3 (including)0.23.3 (including)
DbusFreedesktop0.31 (including)0.31 (including)
DbusFreedesktop0.32 (including)0.32 (including)
DbusFreedesktop0.33 (including)0.33 (including)
DbusFreedesktop0.34 (including)0.34 (including)
DbusFreedesktop0.35 (including)0.35 (including)
DbusFreedesktop0.35.1 (including)0.35.1 (including)
DbusFreedesktop0.35.2 (including)0.35.2 (including)
DbusFreedesktop0.36 (including)0.36 (including)
DbusFreedesktop0.36.1 (including)0.36.1 (including)
DbusFreedesktop0.36.2 (including)0.36.2 (including)
DbusFreedesktop0.50 (including)0.50 (including)
DbusFreedesktop0.60 (including)0.60 (including)
DbusFreedesktop0.61 (including)0.61 (including)
DbusFreedesktop0.62 (including)0.62 (including)
DbusFreedesktop0.90 (including)0.90 (including)
DbusFreedesktop0.91 (including)0.91 (including)
DbusFreedesktop0.92 (including)0.92 (including)
DbusFreedesktop1.0 (including)1.0 (including)
DbusFreedesktop1.0-rc1 (including)1.0-rc1 (including)
DbusFreedesktop1.0-rc2 (including)1.0-rc2 (including)
DbusFreedesktop1.0-rc3 (including)1.0-rc3 (including)
DbusFreedesktop1.1.0 (including)1.1.0 (including)
DbusFreedesktop1.1.1 (including)1.1.1 (including)
DbusFreedesktop1.1.2 (including)1.1.2 (including)
DbusFreedesktop1.1.4 (including)1.1.4 (including)
DbusUbuntudapper*
DbusUbuntugutsy*
DbusUbuntuhardy*
DbusUbuntuintrepid*
DbusUbuntuupstream*

References