4.6
CVE-2008-0595
- EPSS 0.05%
- Published 29.02.2008 19:44:00
- Last modified 09.04.2025 00:30:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Data is provided by the National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version7
Mandrakesoft ≫ Mandrake Linux Version2007
Mandrakesoft ≫ Mandrake Linux Version2007.0_x86_64
Mandrakesoft ≫ Mandrake Linux Version2007.1
Mandrakesoft ≫ Mandrake Linux Version2007.1 Editionx86_64
Mandrakesoft ≫ Mandrake Linux Version2008.0
Mandrakesoft ≫ Mandrake Linux Version2008.0 Editionx86_64
Redhat ≫ Enterprise Linux Version5 Editionclient_workstation
Redhat ≫ Enterprise Linux Version5.0
Freedesktop ≫ Dbus Version < 1.0.3
Freedesktop ≫ Dbus Version >= 1.1.0 < 1.1.20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.118 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.