3.6
CVSSv2

CVE-2009-1189

Published: 27/04/2009 Updated: 07/11/2023
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) prior to 1.2.14 uses incorrect logic to validate a basic type, which allows remote malicious users to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop dbus 0.13

freedesktop dbus 0.60

freedesktop dbus 1.1.2

freedesktop dbus 0.34

freedesktop dbus 0.92

freedesktop dbus 0.50

freedesktop dbus

freedesktop dbus 0.35.1

freedesktop dbus 0.5

freedesktop dbus 0.36.1

freedesktop dbus 0.33

freedesktop dbus 1.0

freedesktop dbus 0.10

freedesktop dbus 0.11

freedesktop dbus 1.1.0

freedesktop dbus 0.2

freedesktop dbus 1.0.2

freedesktop dbus 1.1.20

freedesktop dbus 0.9

freedesktop dbus 1.2.1

freedesktop dbus 0.23.2

freedesktop dbus 0.35

freedesktop dbus 0.91

freedesktop dbus 0.6

freedesktop dbus 0.8

freedesktop dbus 0.36

freedesktop dbus 0.32

freedesktop dbus 0.22

freedesktop dbus 1.1.1

freedesktop dbus 0.4

freedesktop dbus 0.61

freedesktop dbus 0.21

freedesktop dbus 0.35.2

freedesktop dbus 0.23.3

freedesktop dbus 0.20

freedesktop dbus 0.7

freedesktop dbus 0.1

freedesktop dbus 0.62

freedesktop dbus 0.23.1

freedesktop dbus 0.3

freedesktop dbus 0.12

freedesktop dbus 0.90

freedesktop dbus 1.1.4

freedesktop dbus 0.36.2

freedesktop dbus 0.23

freedesktop dbus 0.31

Vendor Advisories

Synopsis Moderate: dbus security update Type/Severity Security Advisory: Moderate Topic Updated dbus packages that fix a security issue are now available for RedHat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Description ...
Debian Bug report logs - #532720 dbus: CVE-2009-1189 incomplete fix for CVE-2008-3834 Package: dbus; Maintainer for dbus is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for dbus is src:dbus (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: ...
It was discovered that the D-Bus library did not correctly validate signatures If a local user sent a specially crafted D-Bus key, they could spoof a valid signature and bypass security policies ...
It was discovered that the dbus_signature_validate function in dbus, a simple interprocess messaging system, is prone to a denial of service attack This issue was caused by an incorrect fix for DSA-1658-1 For the stable distribution (lenny), this problem has been fixed in version 121-5+lenny1 For the oldstable distribution (etch), this problem ...