cbcvebase.
CVE-2008-4311
published 2008-12-10

CVE-2008-4311: The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass…

PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.41%
33.2th percentile
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debiandbus< dbus 1.2.1-5 (bookworm)dbus 1.2.1-5 (bookworm)
freedesktopdbus<= 1.2.4
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus
freedesktopdbus

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.