LWN.net Logo

dbus-glib: privilege escalation

Package(s):dbus-glib CVE #(s):CVE-2013-0292
Created:February 18, 2013 Updated:March 11, 2013
Description: From the Mageia advisory:

A privilege escalation flaw was found in the way dbus-glib, the D-Bus add-on library to integrate the standard D-Bus library with the GLib thread abstraction and main loop, performed filtering of the message sender (message source subject), when the NameOwnerChanged signal was received. A local attacker could use this flaw to escalate their privileges.

Alerts:
Mageia MGASA-2013-0057 2013-02-17
Red Hat RHSA-2013:0568-01 2013-02-26
Oracle ELSA-2013-0568 2013-02-26
Oracle ELSA-2013-0568 2013-02-28
Ubuntu USN-1753-1 2013-02-27
CentOS CESA-2013:0568 2013-03-01
Scientific Linux SL-dbus-20130228 2013-02-28
CentOS CESA-2013:0568 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds