Back to search
CVE-2013-0292
Published: Mar 4, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
33614
exploit
x_refsource_EXPLOIT-DB
MDVSA-2013:071
vendor-advisory
x_refsource_MANDRIVA
52225
third-party-advisory
x_refsource_SECUNIA
dbus-message-sender-priv-esc(82135)
vdb-entry
x_refsource_XF
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=911658
x_refsource_MISC
52375
third-party-advisory
x_refsource_SECUNIA
USN-1753-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2013:0568
vendor-advisory
x_refsource_REDHAT
57985
vdb-entry
x_refsource_BID
52404
third-party-advisory
x_refsource_SECUNIA
[oss-security] 20130215 CVE-2013-0292: authentication bypass due to insufficient checks in dbus-glib < 0.100.1
mailing-list
x_refsource_MLIST
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
x_refsource_CONFIRM
90302
vdb-entry
x_refsource_OSVDB
https://bugs.freedesktop.org/show_bug.cgi?id=60916
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now