CVE-2011-2533
published 2011-06-22CVE-2011-2533: The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in…
PriorityP48low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.29%
20.7th percentile
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.3.2~git20100715.821f99c-1 (bookworm) | dbus 1.3.2~git20100715.821f99c-1 (bookworm) |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | — | — |
| freedesktop | dbus | >= 0 < 1.3.2~git20100715.821f99c-1 | 1.3.2~git20100715.821f99c-1 |
| freedesktop | dbus | >= 0 < 1.3.2~git20100715.821f99c-1 | 1.3.2~git20100715.821f99c-1 |
| freedesktop | dbus | >= 0 < 1.3.2~git20100715.821f99c-1 | 1.3.2~git20100715.821f99c-1 |
| freedesktop | dbus | >= 0 < 1.3.2~git20100715.821f99c-1 | 1.3.2~git20100715.821f99c-1 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dbus: Possibility of symlink attack in /tmp during compilation
vendor_redhat·2011-06-10·CVSS 3.3
CVE-2011-2533 [LOW] dbus: Possibility of symlink attack in /tmp during compilation
dbus: Possibility of symlink attack in /tmp during compilation
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
Statement: This issue is compile-time only and does not affect binary dbus packages, shipped in Red Hat Enterprise Linux 5 and 6. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 5 and 6.
Package: dbus (Red Hat Enterprise Linux 4) - Not affected
Package: dbus (Red Hat Enterprise Linux 5) - Affected
Package: dbus (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2011-2533: dbus - The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users ...
vendor_debian·2011·CVSS 3.3
CVE-2011-2533 [LOW] CVE-2011-2533: dbus - The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users ...
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
Scope: local
bookworm: resolved (fixed in 1.3.2~git20100715.821f99c-1)
bullseye: resolved (fixed in 1.3.2~git20100715.821f99c-1)
forky: resolved (fixed in 1.3.2~git20100715.821f99c-1)
sid: resolved (fixed in 1.3.2~git20100715.821f99c-1)
trixie: resolved (fixed in 1.3.2~git20100715.821f99c-1)
GHSA
GHSA-gh65-c85m-3mv4: The configure script in D-Bus (aka DBus) 1
ghsa_unreviewed·2022-05-17
CVE-2011-2533 [LOW] CWE-59 GHSA-gh65-c85m-3mv4: The configure script in D-Bus (aka DBus) 1
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
OSV
CVE-2011-2533: The configure script in D-Bus (aka DBus) 1
osv·2011-06-22·CVSS 3.3
CVE-2011-2533 [LOW] CVE-2011-2533: The configure script in D-Bus (aka DBus) 1
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
No detection rules found.
No public exploits indexed.
http://cgit.freedesktop.org/dbus/dbus/tree/NEWS?h=dbus-1.2http://www.securitytracker.com/id?1025720https://exchange.xforce.ibmcloud.com/vulnerabilities/68173http://cgit.freedesktop.org/dbus/dbus/tree/NEWS?h=dbus-1.2http://www.securitytracker.com/id?1025720https://exchange.xforce.ibmcloud.com/vulnerabilities/68173
2011-06-22
Published