CVE-2010-1172

CVE Details

Release Date:2010-08-20
Impact:Moderate What is this?

Description


DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.

See more information about CVE-2010-1172 from MITRE CVE dictionary and NIST NVD


NOTE: The following CVSS metrics and score provided are preliminary and subject to review.


CVSS v2 metrics

Base Score: 3.6
Vector String: AV:L/AC:L/Au:N/C:N/I:P/A:P
Version: 2.0
Attack Vector: Local
Attack Complexity: Low
Authentication: None
Confidentiality Impact: None
Integrity Impact: Partial
Availability Impact: Partial

Errata information


PlatformErrataRelease Date
Oracle Linux version 5 (NetworkManager)ELSA-2010-06162010-08-10
Oracle Linux version 5 (dbus-glib)ELSA-2010-06162010-08-10


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete