libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dbus-x11Upgrade dbus-docUpgrade dbus-develUpgrade dbusUpgrade dbus-libs | Dec 1, 2016 | Sep 18, 2012 |
| Debian | — | Upgrade dbusUpgrade glib2.0 | Jul 30, 2024 | Sep 18, 2012 |
| Gentoo Linux | — | Upgrade dev-libs/glib.Upgrade sys-apps/dbus. | Oct 30, 2017 | Sep 18, 2012 |
| Oracle Solaris | — | Upgrade system/library/libdbus to version 1.2.28-0.175.0.12.0.4.0 on Solaris 11.0Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | May 29, 2017 | Sep 18, 2012 |
| Oracle_linux | — | Upgrade dbusUpgrade dbus-develUpgrade dbus-libsUpgrade dbus-x11Upgrade dbus-doc | Oct 16, 2024 | Sep 18, 2012 |
| Suse | — | Upgrade dbus-1-debugsourceUpgrade dbus-1-debuginfo-32bitUpgrade dbus-1-debuginfo-x86Upgrade libdbus-1-3-32bitUpgrade dbus-1-x11-debuginfoUpgrade dbus-1-devel-32bitUpgrade dbus-1-devel-docUpgrade dbus-1-32bitUpgrade dbus-1-develUpgrade libdbus-1-3Upgrade dbus-1-x11Upgrade dbus-1Upgrade dbus-1-x86Upgrade dbus-1-debuginfoUpgrade dbus-1-x11-debugsource | Feb 17, 2015 | Sep 18, 2012 |
| Ubuntu | — | Upgrade dbusUpgrade libdbus-1-3 | Nov 8, 2024 | Sep 18, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub