Lucene search

K
nvd[email protected]NVD:CVE-2013-0292
HistoryMar 05, 2013 - 9:38 p.m.

CVE-2013-0292

2013-03-0521:38:56
CWE-20
web.nvd.nist.gov
2

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.8%

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

Affected configurations

Nvd
Node
freedesktopdbus-glibRange0.100
OR
freedesktopdbus-glibMatch0.72
OR
freedesktopdbus-glibMatch0.73
OR
freedesktopdbus-glibMatch0.74
OR
freedesktopdbus-glibMatch0.76
OR
freedesktopdbus-glibMatch0.78
OR
freedesktopdbus-glibMatch0.80
OR
freedesktopdbus-glibMatch0.82
OR
freedesktopdbus-glibMatch0.84
OR
freedesktopdbus-glibMatch0.86
OR
freedesktopdbus-glibMatch0.88
OR
freedesktopdbus-glibMatch0.90
OR
freedesktopdbus-glibMatch0.92
OR
freedesktopdbus-glibMatch0.94
OR
freedesktopdbus-glibMatch0.96
OR
freedesktopdbus-glibMatch0.98
VendorProductVersionCPE
freedesktopdbus-glib*cpe:2.3:a:freedesktop:dbus-glib:*:*:*:*:*:*:*:*
freedesktopdbus-glib0.72cpe:2.3:a:freedesktop:dbus-glib:0.72:*:*:*:*:*:*:*
freedesktopdbus-glib0.73cpe:2.3:a:freedesktop:dbus-glib:0.73:*:*:*:*:*:*:*
freedesktopdbus-glib0.74cpe:2.3:a:freedesktop:dbus-glib:0.74:*:*:*:*:*:*:*
freedesktopdbus-glib0.76cpe:2.3:a:freedesktop:dbus-glib:0.76:*:*:*:*:*:*:*
freedesktopdbus-glib0.78cpe:2.3:a:freedesktop:dbus-glib:0.78:*:*:*:*:*:*:*
freedesktopdbus-glib0.80cpe:2.3:a:freedesktop:dbus-glib:0.80:*:*:*:*:*:*:*
freedesktopdbus-glib0.82cpe:2.3:a:freedesktop:dbus-glib:0.82:*:*:*:*:*:*:*
freedesktopdbus-glib0.84cpe:2.3:a:freedesktop:dbus-glib:0.84:*:*:*:*:*:*:*
freedesktopdbus-glib0.86cpe:2.3:a:freedesktop:dbus-glib:0.86:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.8%