CVE-2008-4311
published 2008-12-10CVE-2008-4311: The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.41%
33.2th percentile
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.2.1-5 (bookworm) | dbus 1.2.1-5 (bookworm) |
| freedesktop | dbus | <= 1.2.4 | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dbus: incorrect use of [send|receive]_requested_reply policy rule attribute in system.conf
vendor_redhat·2008-12-05·CVSS 4.6
CVE-2008-4311 [MEDIUM] dbus: incorrect use of [send|receive]_requested_reply policy rule attribute in system.conf
dbus: incorrect use of [send|receive]_requested_reply policy rule attribute in system.conf
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: dbus (Red Hat E
Debian
CVE-2008-4311: dbus - The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits ...
vendor_debian·2008·CVSS 4.6
CVE-2008-4311 [MEDIUM] CVE-2008-4311: dbus - The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits ...
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
Scope: local
bookworm: resolved (fixed in 1.2.1-5)
bullseye: resolved (fixed in 1.2.1-5)
forky: resolved (fixed in 1.2.1-5)
sid: resolved (fixed in 1.2.1-5)
trixie: resolved (fixed in 1.2.1-5)
GHSA
GHSA-hpmr-9r6f-w2rr: The default configuration of system
ghsa_unreviewed·2022-05-02
CVE-2008-4311 [MEDIUM] GHSA-hpmr-9r6f-w2rr: The default configuration of system
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
OSV
CVE-2008-4311: The default configuration of system
osv·2008-12-10·CVSS 4.6
CVE-2008-4311 [MEDIUM] CVE-2008-4311: The default configuration of system
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532http://forums.fedoraforum.org/showthread.php?t=206797http://lists.freedesktop.org/archives/dbus/2008-December/010702.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://secunia.com/advisories/33047http://secunia.com/advisories/33055http://secunia.com/advisories/34360http://secunia.com/advisories/34642http://www.securityfocus.com/bid/32674http://www.vupen.com/english/advisories/2008/3355https://bugs.freedesktop.org/show_bug.cgi?id=18229https://bugzilla.redhat.com/show_bug.cgi?id=474895https://exchange.xforce.ibmcloud.com/vulnerabilities/47138https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00436.htmlhttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=503532http://forums.fedoraforum.org/showthread.php?t=206797http://lists.freedesktop.org/archives/dbus/2008-December/010702.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://secunia.com/advisories/33047http://secunia.com/advisories/33055http://secunia.com/advisories/34360http://secunia.com/advisories/34642http://www.securityfocus.com/bid/32674http://www.vupen.com/english/advisories/2008/3355https://bugs.freedesktop.org/show_bug.cgi?id=18229https://bugzilla.redhat.com/show_bug.cgi?id=474895https://exchange.xforce.ibmcloud.com/vulnerabilities/47138https://www.redhat.com/archives/fedora-package-announce/2008-December/msg00436.html
2008-12-10
Published