CVE-2019-12749
published 2019-06-11CVE-2019-12749: dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common…
PriorityP341high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.56%
42.7th percentile
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | dbus | < dbus 1.12.16-1 (bookworm) | dbus 1.12.16-1 (bookworm) |
| freedesktop | dbus | < 1.10.28 | 1.10.28 |
| freedesktop | dbus | >= 0 < 1.12.16-1 | 1.12.16-1 |
| freedesktop | dbus | >= 0 < 1.12.16-1 | 1.12.16-1 |
| freedesktop | dbus | >= 0 < 1.12.16-1 | 1.12.16-1 |
| freedesktop | dbus | >= 0 < 1.12.16-1 | 1.12.16-1 |
| freedesktop | dbus | >= 1.12.0 < 1.12.16 | 1.12.16 |
| freedesktop | dbus | >= 1.13.0 < 1.13.12 | 1.13.12 |
| msrc | cbl2_dbus_1.13.6-9_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_dbus_1.13.6-4_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.1HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hpj-v4f4-7g4j: dbus before 1
ghsa_unreviewed·2022-05-24
CVE-2019-12749 [HIGH] CWE-59 GHSA-2hpj-v4f4-7g4j: dbus before 1
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing auth
OSV
CVE-2019-12749: dbus before 1
osv·2019-06-11·CVSS 7.1
CVE-2019-12749 [HIGH] CVE-2019-12749: dbus before 1
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing auth
Ubuntu
DBus vulnerability
vendor_ubuntu·2019-06-12
CVE-2019-12749 DBus vulnerability
Title: DBus vulnerability
Summary: DBus could allow unintended access to services.
USN-4015-1 fixed a vulnerability in DBus. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Joe Vennix discovered that DBus incorrectly handled DBUS_COOKIE_SHA1
authentication. A local attacker could possibly use this issue to bypass
authentication and connect to DBus servers with elevated privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass
vendor_redhat·2019-06-11·CVSS 7.1
CVE-2019-12749 [HIGH] CWE-287 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass
dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client c
Ubuntu
DBus vulnerability
vendor_ubuntu·2019-06-11
CVE-2019-12749 DBus vulnerability
Title: DBus vulnerability
Summary: DBus could allow unintended access to services.
Joe Vennix discovered that DBus incorrectly handled DBUS_COOKIE_SHA1
authentication. A local attacker could possibly use this issue to bypass
authentication and connect to DBus servers with elevated privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Microsoft
dbus before 1.10.28 1.12.x before 1.12.16 and 1.13.x before 1.13.12 as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some less common uses of dbus-daemon) allows cookie spoofing beca
vendor_msrc·2019-06-11·CVSS 7.1
CVE-2019-12749 [HIGH] CWE-59 dbus before 1.10.28 1.12.x before 1.12.16 and 1.13.x before 1.13.12 as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some less common uses of dbus-daemon) allows cookie spoofing beca
dbus before 1.10.28 1.12.x before 1.12.16 and 1.13.x before 1.13.12 as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some less common uses of dbus-daemon) allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case this could result in the DBusServer reusing a cookie that is known to the malicious client and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid allowing authenticatio
Debian
CVE-2019-12749: dbus - dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used i...
vendor_debian·2019·CVSS 7.1
CVE-2019-12749 [HIGH] CVE-2019-12749: dbus - dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used i...
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing auth
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass [fedora-all]
bugzilla·2019-06-17·CVSS 7.1
CVE-2019-12749 [HIGH] CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass [fedora-all]
CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass
bugzilla·2019-06-11·CVSS 7.1
CVE-2019-12749 [HIGH] CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass
CVE-2019-12749 dbus: DBusServer DBUS_COOKIE_SHA1 authentication bypass
A flaw was discovered in dbus where the implementation of DBUS_COOKIE_SHA1 is susceptible to a symbolic link attack. A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause the DBusServer to read and write in unintended locations. This could result in authentication bypass.
Discussion:
Acknowledgments:
Name: the D-Bus project
Upstream: Joe Vennix (Apple Information Security)
---
Its public now: https://www.openwall.com/lists/oss-security/2019/06/11/2
---
Upstream patch: https://gitlab.freedesktop.org/dbus/dbus/commit/47b1a4c41004bf494b87370987b222c934b19016
---
Created dbus tracking bugs for this issue:
Affects: fedora-all [bug 1720995]
---
As per
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00092.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00026.htmlhttp://www.openwall.com/lists/oss-security/2019/06/11/2http://www.securityfocus.com/bid/108751https://access.redhat.com/errata/RHSA-2019:1726https://access.redhat.com/errata/RHSA-2019:2868https://access.redhat.com/errata/RHSA-2019:2870https://access.redhat.com/errata/RHSA-2019:3707https://lists.debian.org/debian-lts-announce/2019/06/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2CQF37O73VH2JDVX2ILX2KD2KLXLQOU/https://seclists.org/bugtraq/2019/Jun/16https://security.gentoo.org/glsa/201909-08https://usn.ubuntu.com/4015-1/https://usn.ubuntu.com/4015-2/https://www.debian.org/security/2019/dsa-4462https://www.openwall.com/lists/oss-security/2019/06/11/2http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00092.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00026.htmlhttp://www.openwall.com/lists/oss-security/2019/06/11/2http://www.securityfocus.com/bid/108751https://access.redhat.com/errata/RHSA-2019:1726https://access.redhat.com/errata/RHSA-2019:2868https://access.redhat.com/errata/RHSA-2019:2870https://access.redhat.com/errata/RHSA-2019:3707https://lists.debian.org/debian-lts-announce/2019/06/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V2CQF37O73VH2JDVX2ILX2KD2KLXLQOU/https://seclists.org/bugtraq/2019/Jun/16https://security.gentoo.org/glsa/201909-08https://security.netapp.com/advisory/ntap-20241206-0010/https://usn.ubuntu.com/4015-1/https://usn.ubuntu.com/4015-2/https://www.debian.org/security/2019/dsa-4462https://www.openwall.com/lists/oss-security/2019/06/11/2
2019-06-11
Published