The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dbus | Freedesktop | * | 1.2.4 (including) |
Dbus | Freedesktop | 0.1 (including) | 0.1 (including) |
Dbus | Freedesktop | 0.2 (including) | 0.2 (including) |
Dbus | Freedesktop | 0.3 (including) | 0.3 (including) |
Dbus | Freedesktop | 0.4 (including) | 0.4 (including) |
Dbus | Freedesktop | 0.5 (including) | 0.5 (including) |
Dbus | Freedesktop | 0.6 (including) | 0.6 (including) |
Dbus | Freedesktop | 0.7 (including) | 0.7 (including) |
Dbus | Freedesktop | 0.8 (including) | 0.8 (including) |
Dbus | Freedesktop | 0.9 (including) | 0.9 (including) |
Dbus | Freedesktop | 0.10 (including) | 0.10 (including) |
Dbus | Freedesktop | 0.11 (including) | 0.11 (including) |
Dbus | Freedesktop | 0.12 (including) | 0.12 (including) |
Dbus | Freedesktop | 0.13 (including) | 0.13 (including) |
Dbus | Freedesktop | 0.20 (including) | 0.20 (including) |
Dbus | Freedesktop | 0.21 (including) | 0.21 (including) |
Dbus | Freedesktop | 0.22 (including) | 0.22 (including) |
Dbus | Freedesktop | 0.23 (including) | 0.23 (including) |
Dbus | Freedesktop | 0.23.1 (including) | 0.23.1 (including) |
Dbus | Freedesktop | 0.23.2 (including) | 0.23.2 (including) |
Dbus | Freedesktop | 0.23.3 (including) | 0.23.3 (including) |
Dbus | Freedesktop | 0.31 (including) | 0.31 (including) |
Dbus | Freedesktop | 0.32 (including) | 0.32 (including) |
Dbus | Freedesktop | 0.33 (including) | 0.33 (including) |
Dbus | Freedesktop | 0.34 (including) | 0.34 (including) |
Dbus | Freedesktop | 0.35 (including) | 0.35 (including) |
Dbus | Freedesktop | 0.35.1 (including) | 0.35.1 (including) |
Dbus | Freedesktop | 0.35.2 (including) | 0.35.2 (including) |
Dbus | Freedesktop | 0.36 (including) | 0.36 (including) |
Dbus | Freedesktop | 0.36.1 (including) | 0.36.1 (including) |
Dbus | Freedesktop | 0.36.2 (including) | 0.36.2 (including) |
Dbus | Freedesktop | 0.50 (including) | 0.50 (including) |
Dbus | Freedesktop | 0.60 (including) | 0.60 (including) |
Dbus | Freedesktop | 0.61 (including) | 0.61 (including) |
Dbus | Freedesktop | 0.62 (including) | 0.62 (including) |
Dbus | Freedesktop | 0.90 (including) | 0.90 (including) |
Dbus | Freedesktop | 0.91 (including) | 0.91 (including) |
Dbus | Freedesktop | 0.92 (including) | 0.92 (including) |
Dbus | Freedesktop | 1.0 (including) | 1.0 (including) |
Dbus | Freedesktop | 1.0-rc1 (including) | 1.0-rc1 (including) |
Dbus | Freedesktop | 1.0-rc2 (including) | 1.0-rc2 (including) |
Dbus | Freedesktop | 1.0-rc3 (including) | 1.0-rc3 (including) |
Dbus | Freedesktop | 1.1.0 (including) | 1.1.0 (including) |
Dbus | Freedesktop | 1.1.1 (including) | 1.1.1 (including) |
Dbus | Freedesktop | 1.1.2 (including) | 1.1.2 (including) |
Dbus | Freedesktop | 1.1.4 (including) | 1.1.4 (including) |
Dbus | Ubuntu | dapper | * |
Dbus | Ubuntu | gutsy | * |
Dbus | Ubuntu | hardy | * |
Dbus | Ubuntu | intrepid | * |
Dbus | Ubuntu | upstream | * |