CVE-2005-0201
published 2005-06-29CVE-2005-0201: D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary…
PriorityP411low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.43%
34.8th percentile
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-bus | d-bus | <= 0.22 | — |
| debian | dbus | < dbus 0.22 (bookworm) | dbus 0.22 (bookworm) |
| freedesktop | dbus | >= 0 < 0.22 | 0.22 |
| freedesktop | dbus | >= 0 < 0.22 | 0.22 |
| freedesktop | dbus | >= 0 < 0.22 | 0.22 |
| freedesktop | dbus | >= 0 < 0.22 | 0.22 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
dbus vulnerability
vendor_ubuntu·2005-06-28
CVE-2005-0201 dbus vulnerability
Title: dbus vulnerability
Summary: dbus vulnerability
Besides providing the global system-wide communication bus, dbus also
offers per-user "session" buses which applications in an user's
session can create and use to communicate with each other. Daniel
Reed discovered that the default configuration of the session dbus
allowed a local user to connect to another user's session bus if its
address was known. The fixed packages restrict the default permissions
to the user who owns the session dbus instance.
Please note that a standard Ubuntu installation does not use the
session bus for anything, so this can only be exploited if you are
using custom software which uses it.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-01-31·CVSS 2.1
CVE-2005-0201 [LOW] security flaw
security flaw
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
Debian
CVE-2005-0201: dbus - D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the s...
vendor_debian·2005·CVSS 2.1
CVE-2005-0201 [LOW] CVE-2005-0201: dbus - D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the s...
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
Scope: local
bookworm: resolved (fixed in 0.22)
bullseye: resolved (fixed in 0.22)
forky: resolved (fixed in 0.22)
sid: resolved (fixed in 0.22)
trixie: resolved (fixed in 0.22)
GHSA
GHSA-42r7-php7-668w: D-BUS (dbus) before 0
ghsa_unreviewed·2022-05-01
CVE-2005-0201 [LOW] GHSA-42r7-php7-668w: D-BUS (dbus) before 0
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
OSV
CVE-2005-0201: D-BUS (dbus) before 0
osv·2005-06-29·CVSS 2.1
CVE-2005-0201 [LOW] CVE-2005-0201: D-BUS (dbus) before 0
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/14119http://secunia.com/advisories/15638http://secunia.com/advisories/15833http://secunia.com/advisories/15844http://securitytracker.com/id?1013075http://www.auscert.org.au/render.html?it=5156http://www.mandriva.com/security/advisories?name=MDKSA-2005:105http://www.redhat.com/support/errata/RHSA-2005-102.htmlhttp://www.securityfocus.com/bid/12435https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10973https://usn.ubuntu.com/144-1/http://secunia.com/advisories/14119http://secunia.com/advisories/15638http://secunia.com/advisories/15833http://secunia.com/advisories/15844http://securitytracker.com/id?1013075http://www.auscert.org.au/render.html?it=5156http://www.mandriva.com/security/advisories?name=MDKSA-2005:105http://www.redhat.com/support/errata/RHSA-2005-102.htmlhttp://www.securityfocus.com/bid/12435https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10973https://usn.ubuntu.com/144-1/
2005-06-29
Published