|
Pardus: Dbus: Security Bypass |
|
|
|
Posted by Benjamin D. Thomas
|
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-04 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-01-23
Severity: 3
Type: Local
------------------------------------------------------------------------
Summary
=======
The default configuration of system.conf in D-Bus (aka DBus) before
1.2.6 omits the send_type attribute in certain rules.
Description
===========
This vulnerability allows local users to bypass intended access
restrictions by sending messages, related to send_requested_reply; and
possibly receiving messages, related to receive_requested_reply.
Affected packages:
Pardus 2008:
dbus, all before 1.2.4.4-41-16
Resolution
==========
There are update(s) for dbus. You can update them via Package Manager or
with a single command from console:
pisi up dbus
References
==========
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4311
|