CVE-2008-0595
published 2008-02-29CVE-2008-0595: dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully…
PriorityP413medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.41%
33.1th percentile
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.1.20-1 (bookworm) | dbus 1.1.20-1 (bookworm) |
| fedoraproject | fedora | — | — |
| freedesktop | dbus | < 1.0.3 | 1.0.3 |
| freedesktop | dbus | >= 0 < 1.1.20-1 | 1.1.20-1 |
| freedesktop | dbus | >= 0 < 1.1.20-1 | 1.1.20-1 |
| freedesktop | dbus | >= 0 < 1.1.20-1 | 1.1.20-1 |
| freedesktop | dbus | >= 0 < 1.1.20-1 | 1.1.20-1 |
| freedesktop | dbus | >= 1.1.0 < 1.1.20 | 1.1.20 |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
D-Bus vulnerabilities
vendor_ubuntu·2008-10-14·CVSS 4.6
CVE-2008-0595 [MEDIUM] D-Bus vulnerabilities
Title: D-Bus vulnerabilities
Summary: D-Bus vulnerabilities
Havoc Pennington discovered that the D-Bus daemon did not correctly
validate certain security policies. If a local user sent a specially
crafted D-Bus request, they could bypass security policies that had a
"send_interface" defined. (CVE-2008-0595)
It was discovered that the D-Bus library did not correctly validate
certain corrupted signatures. If a local user sent a specially crafted
D-Bus request, they could crash applications linked against the D-Bus
library, leading to a denial of service. (CVE-2008-3834)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
dbus security policy circumvention
vendor_redhat·2008-02-27·CVSS 4.6
CVE-2008-0595 [MEDIUM] dbus security policy circumvention
dbus security policy circumvention
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Debian
CVE-2008-0595: dbus - dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_inte...
vendor_debian·2008·CVSS 4.6
CVE-2008-0595 [MEDIUM] CVE-2008-0595: dbus - dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_inte...
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Scope: local
bookworm: resolved (fixed in 1.1.20-1)
bullseye: resolved (fixed in 1.1.20-1)
forky: resolved (fixed in 1.1.20-1)
sid: resolved (fixed in 1.1.20-1)
trixie: resolved (fixed in 1.1.20-1)
GHSA
GHSA-r2x7-p32r-g3vj: dbus-daemon in D-Bus before 1
ghsa_unreviewed·2022-05-01
CVE-2008-0595 [MEDIUM] CWE-863 GHSA-r2x7-p32r-g3vj: dbus-daemon in D-Bus before 1
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
OSV
CVE-2008-0595: dbus-daemon in D-Bus before 1
osv·2008-02-29·CVSS 4.6
CVE-2008-0595 [MEDIUM] CVE-2008-0595: dbus-daemon in D-Bus before 1
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)
bugzilla·2008-07-09·CVSS 6.8
CVE-2008-3104 [MEDIUM] CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)
CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)
Security vulnerabilities in the Java Runtime Environment may allow an untrusted
applet that is loaded from a remote system to circumvent network access
restrictions and establish socket connections to certain services running on the
local host, as if it were loaded from the system that the applet is running on.
This may allow the untrusted remote applet the ability to exploit any security
vulnerabilities existing in the services it has connected to.
Discussion:
This was resolved via:
http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2
Bugzilla
CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
bugzilla·2008-07-09·CVSS 10.0
CVE-2008-3112 [CRITICAL] CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
Sunalert, 238905, Second Issue
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application downloaded from a website to create arbitrary files with the
permissions of the user running the untrusted Java Web Start application.
Discussion:
This was resolved via:
http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0636.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0638.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0906.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0594.html (RHE
Bugzilla
CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)
bugzilla·2008-07-09·CVSS 10.0
CVE-2008-3113 [CRITICAL] CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)
CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)
Sunalert, 238905, Third Issue
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application downloaded from a website to create or delete arbitrary files with
the permissions of the user running the untrusted Java Web Start application.
Discussion:
This was resolved via:
http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0636.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0638.html (Satellite 5.1)
Bugzilla
CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)
bugzilla·2008-07-09·CVSS 5.0
CVE-2008-3114 [MEDIUM] CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)
CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location (6704074)
Sunalert, 238905, Fourth Issue
A vulnerability in Java Web Start may allow an untrusted Java Web Start
application to determine the location of the Java Web Start cache.
Discussion:
This was resolved via:
http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0636.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0638.html (Satellite 5.1)
http://rhn.redhat.com/errata/RHSA-2008-0906.html (RHEL4, RHEL5)
http://rhn.redhat.com/errata/RHSA-2008-0594.html (RHEL4, RHEL5)
Bugzilla
CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)
bugzilla·2008-07-09·CVSS 10.0
CVE-2008-3111 [CRITICAL] CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)
CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)
Sunalert, 238905, First Issue
Buffer overflow vulnerabilities in Java Web Start may allow an untrusted Java
Web Start application to elevate its privileges. For example, an untrusted Java
Web Start application may grant itself permissions to read and write local files
or execute local applications that are accessible to the user running the
untrusted application.
Discussion:
This issue has been corrected via:
Red Hat Enterprise Linux version 4 Extras (RHSA-2008:0595 (java-1.5.0-sun) and RHSA-2008:0790 (java-1.5.0-ibm))
RHEL Supplementary version 5 (RHSA-2008:0595 (java-1.5.0-sun) and RHSA-2008:0790 (java-1.5.0-ibm))
Red Hat Network Satellite Server 5.1 (RHEL v.4 AS) (RHSA-2008:0636 (java-1.5.0-sun) and RHSA-2008:06
Bugzilla
CVE-2008-0595 dbus security policy circumvention
bugzilla·2008-02-11·CVSS 4.6
CVE-2008-0595 [MEDIUM] CVE-2008-0595 dbus security policy circumvention
CVE-2008-0595 dbus security policy circumvention
Havoc Pennington discovered a flaw in the way the dbus-daemon applies its
security policy.
Ray Strode describes it as such:
When evaluating whether or not to invoke a method call, the bus daemon
will look at the security policy and try to determine whether or not the
caller is allowed access to the method call.
Many dbus services have lines in their security policy of the form:
to explicitly whitelist the methods of a particular interface for users
of a specific policy context.
Normally dbus method calls are invoked fully qualified. That is to say
the interface the method belongs to is passed to the bus daemon along
with the method name of the method call. The bus daemon does not
require method calls to be fully qualified, however. If
http://lists.freedesktop.org/archives/dbus/2008-February/009401.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://secunia.com/advisories/29148http://secunia.com/advisories/29160http://secunia.com/advisories/29171http://secunia.com/advisories/29173http://secunia.com/advisories/29281http://secunia.com/advisories/29323http://secunia.com/advisories/30869http://secunia.com/advisories/32281http://securitytracker.com/id?1019512http://wiki.rpath.com/Advisories:rPSA-2008-0099http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0099http://www.debian.org/security/2008/dsa-1599http://www.j5live.com/2008/02/27/announce-d-bus-1120-conisten-water-released/http://www.mandriva.com/security/advisories?name=MDVSA-2008:054http://www.redhat.com/support/errata/RHSA-2008-0159.htmlhttp://www.securityfocus.com/archive/1/489280/100/0/threadedhttp://www.securityfocus.com/bid/28023http://www.ubuntu.com/usn/usn-653-1http://www.vupen.com/english/advisories/2008/0694https://issues.rpath.com/browse/RPL-2282https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9353https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00893.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00911.htmlhttp://lists.freedesktop.org/archives/dbus/2008-February/009401.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://secunia.com/advisories/29148http://secunia.com/advisories/29160http://secunia.com/advisories/29171http://secunia.com/advisories/29173http://secunia.com/advisories/29281http://secunia.com/advisories/29323http://secunia.com/advisories/30869http://secunia.com/advisories/32281http://securitytracker.com/id?1019512http://wiki.rpath.com/Advisories:rPSA-2008-0099http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0099http://www.debian.org/security/2008/dsa-1599http://www.j5live.com/2008/02/27/announce-d-bus-1120-conisten-water-released/http://www.mandriva.com/security/advisories?name=MDVSA-2008:054http://www.redhat.com/support/errata/RHSA-2008-0159.htmlhttp://www.securityfocus.com/archive/1/489280/100/0/threadedhttp://www.securityfocus.com/bid/28023http://www.ubuntu.com/usn/usn-653-1http://www.vupen.com/english/advisories/2008/0694https://issues.rpath.com/browse/RPL-2282https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9353https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00893.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00911.html
2008-02-29
Published