The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
2011-06-22T23:55:00.683
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.3 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | freedesktop | dbus | 1.2.1 | Yes |
Application | freedesktop | dbus | 1.2.3 | Yes |
Application | freedesktop | dbus | 1.2.4 | Yes |
Application | freedesktop | dbus | 1.2.6 | Yes |
Application | freedesktop | dbus | 1.2.8 | Yes |
Application | freedesktop | dbus | 1.2.10 | Yes |
Application | freedesktop | dbus | 1.2.12 | Yes |
Application | freedesktop | dbus | 1.2.14 | Yes |
Application | freedesktop | dbus | 1.2.16 | Yes |
Application | freedesktop | dbus | 1.2.18 | Yes |
Application | freedesktop | dbus | 1.2.20 | Yes |
Application | freedesktop | dbus | 1.2.22 | Yes |
Application | freedesktop | dbus | 1.2.24 | Yes |
Application | freedesktop | dbus | 1.2.26 | Yes |