Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-0292
HistoryFeb 15, 2013 - 12:00 a.m.

CVE-2013-0292

2013-02-1500:00:00
ubuntu.com
ubuntu.com
14

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

9.8%

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before
0.100.1 does not properly verify the sender of NameOwnerChanged signals,
which allows local users to gain privileges via a spoofed signal.

Bugs

Notes

Author Note
seth-arnold local privilege escalation demonstrated with pam_fprintd dbus-glib is deprecated
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchdbus-glib< 0.84-1ubuntu0.3UNKNOWN
ubuntu11.10noarchdbus-glib< 0.94-4ubuntu0.1UNKNOWN
ubuntu12.04noarchdbus-glib< 0.98-1ubuntu1.1UNKNOWN
ubuntu12.10noarchdbus-glib< 0.100-1ubuntu0.1UNKNOWN

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

9.8%