Name CVE-2008-0595 First vendor Publication 2008-02-29
Vendor Cve Last vendor Modification 2024-02-01

dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0595

Definition Id: oval:org.mitre.oval:def:20329
Oval ID: oval:org.mitre.oval:def:20329
Title: DSA-1599-1 dbus
Description: Havoc Pennington discovered that DBus, a simple interprocess messaging system, performs insufficient validation of security policies, which might allow local privilege escalation.
Family: unix Class: patch
Reference(s): DSA-1599-1
Version: 5
Platform(s): Debian GNU/Linux 4.0
Product(s): dbus
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22397
Oval ID: oval:org.mitre.oval:def:22397
Title: ELSA-2008:0159: dbus security update (Moderate)
Description: dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Family: unix Class: patch
Reference(s): ELSA-2008:0159-01
Version: 6
Platform(s): Oracle Linux 5
Product(s): dbus
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:8119
Oval ID: oval:org.mitre.oval:def:8119
Title: DSA-1599 dbus -- programming error
Description: Havoc Pennington discovered that DBus, a simple interprocess messaging system, performs insufficient validation of security policies, which might allow local privilege escalation.
Family: unix Class: patch
Reference(s): DSA-1599
Version: 3
Platform(s): Debian GNU/Linux 4.0
Product(s): dbus
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:9353
Oval ID: oval:org.mitre.oval:def:9353
Title: dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Description: dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Family: unix Class: vulnerability
Reference(s): CVE-2008-0595
Version: 5
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Definition Synopsis:

