// For flags

CVE-2008-0595

dbus security policy circumvention

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.

dbus-daemon en D-Bus anterior a 1.0.3 y 1.1.x anterior a 1.1.20, reconoce atributos de send_interface en directivas de permiso en la política de seguridad sólo para llamadas a métodos completamente cualificados, esto permite a usuarios locales evitar las restricciones de acceso pretendidas mediante llamadas a métodos con una interfaz NULL.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-02-05 CVE Reserved
  • 2008-02-29 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-863: Incorrect Authorization
CAPEC
References (28)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
7
Search vendor "Fedoraproject" for product "Fedora" and version "7"
-
Affected
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2007
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007"
-
Affected
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2007.0_x86_64
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007.0_x86_64"
-
Affected
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2007.1
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007.1"
-
Affected
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2007.1
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2007.1"
x86_64
Affected
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2008.0
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2008.0"
-
Affected
Mandrakesoft
Search vendor "Mandrakesoft"
Mandrake Linux
Search vendor "Mandrakesoft" for product "Mandrake Linux"
2008.0
Search vendor "Mandrakesoft" for product "Mandrake Linux" and version "2008.0"
x86_64
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
5
Search vendor "Redhat" for product "Enterprise Linux" and version "5"
client_workstation
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
5.0
Search vendor "Redhat" for product "Enterprise Linux" and version "5.0"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
< 1.0.3
Search vendor "Freedesktop" for product "Dbus" and version " < 1.0.3"
-
Affected
Freedesktop
Search vendor "Freedesktop"
Dbus
Search vendor "Freedesktop" for product "Dbus"
>= 1.1.0 < 1.1.20
Search vendor "Freedesktop" for product "Dbus" and version " >= 1.1.0 < 1.1.20"
-
Affected