The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dbus | Freedesktop | 1.2.1 | 1.2.1 |
Dbus | Freedesktop | 1.2.3 | 1.2.3 |
Dbus | Freedesktop | 1.2.4 | 1.2.4 |
Dbus | Freedesktop | 1.2.6 | 1.2.6 |
Dbus | Freedesktop | 1.2.8 | 1.2.8 |
Dbus | Freedesktop | 1.2.10 | 1.2.10 |
Dbus | Freedesktop | 1.2.12 | 1.2.12 |
Dbus | Freedesktop | 1.2.14 | 1.2.14 |
Dbus | Freedesktop | 1.2.16 | 1.2.16 |
Dbus | Freedesktop | 1.2.18 | 1.2.18 |
Dbus | Freedesktop | 1.2.20 | 1.2.20 |
Dbus | Freedesktop | 1.2.22 | 1.2.22 |
Dbus | Freedesktop | 1.2.24 | 1.2.24 |
Dbus | Freedesktop | 1.2.26 | 1.2.26 |
Dbus | Ubuntu | lucid | * |
Dbus | Ubuntu | upstream | * |