Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4311
HistoryDec 10, 2008 - 12:00 a.m.

CVE-2008-4311

2008-12-1000:00:00
ubuntu.com
ubuntu.com
13

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6
omits the send_type attribute in certain rules, which allows local users to
bypass intended access restrictions by (1) sending messages, related to
send_requested_reply; and possibly (2) receiving messages, related to
receive_requested_reply.

Notes

Author Note
kees Ubuntu’s dbus clients are not believed to be vulnerable.

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

10.1%