CVE-2012-3524
published 2012-09-18CVE-2012-3524: libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and…
PriorityP340medium6.9CVSS 2.0
AVLACMAuNCCICAC
EXPLOIT
EPSS
4.51%
90.5th percentile
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dbus | < dbus 1.6.8-1 (bookworm) | dbus 1.6.8-1 (bookworm) |
| debian | glib2.0 | < dbus 1.6.8-1 (bookworm) | dbus 1.6.8-1 (bookworm) |
| freedesktop | dbus | >= 0 < 1.6.8-1 | 1.6.8-1 |
| freedesktop | dbus | >= 0 < 1.6.8-1 | 1.6.8-1 |
| freedesktop | dbus | >= 0 < 1.6.8-1 | 1.6.8-1 |
| freedesktop | dbus | >= 0 < 1.6.8-1 | 1.6.8-1 |
| freedesktop | libdbus | <= 1.5.12 | — |
| freedesktop | libdbus | — | — |
| freedesktop | libdbus | — | — |
| freedesktop | libdbus | — | — |
| freedesktop | libdbus | — | — |
| freedesktop | libdbus | — | — |
| freedesktop | libdbus | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DBus regressions
vendor_ubuntu·2012-10-04
CVE-2012-3524 DBus regressions
Title: DBus regressions
Summary: DBus could be made to run programs as an administrator.
USN-1576-1 fixed vulnerabilities in DBus. The update caused a regression
for certain services launched from the activation helper, and caused an
unclean shutdown on upgrade. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Sebastian Krahmer discovered that DBus incorrectly handled environment
variables when running with elevated privileges. A local attacker could
possibly exploit this flaw with a setuid binary and gain root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
DBus vulnerability
vendor_ubuntu·2012-09-20
CVE-2012-3524 DBus vulnerability
Title: DBus vulnerability
Summary: DBus could be made to run programs as an administrator.
Sebastian Krahmer discovered that DBus incorrectly handled environment
variables when running with elevated privileges. A local attacker could
possibly exploit this flaw with a setuid binary and gain root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dbus: privilege escalation when libdbus is used in setuid/setgid application
vendor_redhat·2012-09-12·CVSS 6.9
CVE-2012-3524 [MEDIUM] CWE-426 dbus: privilege escalation when libdbus is used in setuid/setgid application
dbus: privilege escalation when libdbus is used in setuid/setgid application
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
Package: dbus (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-3524: dbus - libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X...
vendor_debian·2012·CVSS 6.9
CVE-2012-3524 [MEDIUM] CVE-2012-3524: dbus - libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X...
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
Scope: local
bookworm: resolved (fixed in 1.6.8-1)
bullseye: resolved (fixed in 1.6.8-1)
forky: resolved (fixed in 1.6.8-1)
sid: resolved (fixed in 1.6.8-1)
trixie: resolved (fixed in 1.6.8-1)
GHSA
GHSA-qw63-7rfw-9cx5: libdbus 1
ghsa_unreviewed·2022-05-17
CVE-2012-3524 [MEDIUM] GHSA-qw63-7rfw-9cx5: libdbus 1
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
OSV
CVE-2012-3524: libdbus 1
osv·2012-09-18·CVSS 6.9
CVE-2012-3524 [MEDIUM] CVE-2012-3524: libdbus 1
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
No detection rules found.
Bugzilla
CVE-2012-4425 spice-gtk/glib: Possible privilege escalation via un-sanitized environment variable
bugzilla·2012-09-14·CVSS 6.9
CVE-2012-4425 [MEDIUM] CVE-2012-4425 spice-gtk/glib: Possible privilege escalation via un-sanitized environment variable
CVE-2012-4425 spice-gtk/glib: Possible privilege escalation via un-sanitized environment variable
It was discovered that the spice-gtk setuid helper application, spice-client-glib-usb-acl-helper, did not clear the environment variables read by the libraries it uses. A local attacker could possibly use this flaw to escalate their privileges by setting specific environment variables before running the helper application.
This flaw is similar to CVE-2012-3524
Discussion:
Created spice-gtk tracking bugs for this issue
Affects: fedora-all [bug 857228]
---
Acknowledgement:
Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
reporting this issue.
---
Reference:
http://seclists.org/oss-sec/2012/q3/470
---
Created glib2 tracking bugs for this issue
Affects: fed
Bugzilla
CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]
bugzilla·2012-09-13·CVSS 6.9
CVE-2012-3524 [MEDIUM] CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]
CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/
Bugzilla
CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]
bugzilla·2012-09-13·CVSS 6.9
CVE-2012-3524 [MEDIUM] CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]
CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/
Bugzilla
CVE-2012-3524 dbus: privilege escalation when libdbus is used in setuid/setgid application
bugzilla·2012-08-10·CVSS 6.9
CVE-2012-3524 [MEDIUM] CVE-2012-3524 dbus: privilege escalation when libdbus is used in setuid/setgid application
CVE-2012-3524 dbus: privilege escalation when libdbus is used in setuid/setgid application
X.org has traditionally been suid root so that users could utilize "startx" (or similar scripts) to start X from the command line as a user. X.org does not sanitize the environment when starting, which means it will be aware of, and pass along, environment variables. When X.org is using the DBus backend, specifically versions 1.5.x or newer, the DBUS_SYSTEM_BUS_ADDRESS environment variable is passed along to libdbus. The DBUS system address can take a unixexec (Executed Subprocess on UNIX) transport [1] which allows one to specify a binary to execute and arguments to pass to it.
Because the DBUS_SYSTEM_BUS_ADDRESS environment variable is not scrubbed by X, this environment variable is passed along
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1261.htmlhttp://secunia.com/advisories/50537http://secunia.com/advisories/50544http://secunia.com/advisories/50710http://stealth.openwall.net/null/dzug.chttp://www.exploit-db.com/exploits/21323http://www.mandriva.com/security/advisories?name=MDVSA-2013:070http://www.mandriva.com/security/advisories?name=MDVSA-2013:083http://www.openwall.com/lists/oss-security/2012/07/10/4http://www.openwall.com/lists/oss-security/2012/07/26/1http://www.openwall.com/lists/oss-security/2012/09/12/6http://www.openwall.com/lists/oss-security/2012/09/14/2http://www.openwall.com/lists/oss-security/2012/09/17/2http://www.securityfocus.com/bid/55517http://www.ubuntu.com/usn/USN-1576-1http://www.ubuntu.com/usn/USN-1576-2https://bugs.freedesktop.org/show_bug.cgi?id=52202https://bugzilla.novell.com/show_bug.cgi?id=697105https://bugzilla.redhat.com/show_bug.cgi?id=847402http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00094.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1261.htmlhttp://secunia.com/advisories/50537http://secunia.com/advisories/50544http://secunia.com/advisories/50710http://stealth.openwall.net/null/dzug.chttp://www.exploit-db.com/exploits/21323http://www.mandriva.com/security/advisories?name=MDVSA-2013:070http://www.mandriva.com/security/advisories?name=MDVSA-2013:083http://www.openwall.com/lists/oss-security/2012/07/10/4http://www.openwall.com/lists/oss-security/2012/07/26/1http://www.openwall.com/lists/oss-security/2012/09/12/6http://www.openwall.com/lists/oss-security/2012/09/14/2http://www.openwall.com/lists/oss-security/2012/09/17/2http://www.securityfocus.com/bid/55517http://www.ubuntu.com/usn/USN-1576-1http://www.ubuntu.com/usn/USN-1576-2https://bugs.freedesktop.org/show_bug.cgi?id=52202https://bugzilla.novell.com/show_bug.cgi?id=697105https://bugzilla.redhat.com/show_bug.cgi?id=847402
2012-09-18
Published