cbcvebase.
CVE-2008-0595
published 2008-02-29

CVE-2008-0595: dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully…

PriorityP413medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.41%
33.1th percentile
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandbus< dbus 1.1.20-1 (bookworm)dbus 1.1.20-1 (bookworm)
fedoraprojectfedora
freedesktopdbus< 1.0.31.0.3
freedesktopdbus>= 0 < 1.1.20-11.1.20-1
freedesktopdbus>= 0 < 1.1.20-11.1.20-1
freedesktopdbus>= 0 < 1.1.20-11.1.20-1
freedesktopdbus>= 0 < 1.1.20-11.1.20-1
freedesktopdbus>= 1.1.0 < 1.1.201.1.20
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
mandrakesoftmandrake_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.