Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2012-3524Untrusted Search Path in Libdbus

Severity
6.9MEDIUMNVD
EPSS
52.4%
top 2.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedSep 18
Latest updateMay 17

Description

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages2 packages

NVDfreedesktop/libdbus1.5.12+6
Debianfreedesktop/dbus< 1.6.8-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-qw63-7rfw-9cx5: libdbus 12022-05-17
CVEList
CVE-2012-3524: libdbus 12012-09-18
OSV
CVE-2012-3524: libdbus 12012-09-18

💥Exploits & PoCs

1
Exploit-DB
libdbus - 'DBUS_SYSTEM_BUS_ADDRESS' Local Privilege Escalation2012-07-17

📋Vendor Advisories

4
Ubuntu
DBus regressions2012-10-04
Ubuntu
DBus vulnerability2012-09-20
Red Hat
dbus: privilege escalation when libdbus is used in setuid/setgid application2012-09-12
Debian
CVE-2012-3524: dbus - libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X...2012

💬Community

4
Bugzilla
CVE-2012-4425 spice-gtk/glib: Possible privilege escalation via un-sanitized environment variable2012-09-14
Bugzilla
CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]2012-09-13
Bugzilla
CVE-2012-3524 X.org: arbitrary code execution as root when libdbus >= 1.5 is used [fedora-all]2012-09-13
Bugzilla
CVE-2012-3524 dbus: privilege escalation when libdbus is used in setuid/setgid application2012-08-10
CVE-2012-3524 — Untrusted Search Path in Libdbus | cvebase