3.6
CVSSv2

CVE-2010-1172

Published: 20/08/2010 Updated: 17/08/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop dbus-glib 0.73

Vendor Advisories

Synopsis Moderate: dbus-glib security update Type/Severity Security Advisory: Moderate Topic Updated dbus-glib packages that fix one security issue are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerabili ...
Debian Bug report logs - #592753 libdbus-glib-1-dev: CVE-2010-1172 property access not validated Package: libdbus-glib-1-dev; Maintainer for libdbus-glib-1-dev is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for libdbus-glib-1-dev is src:dbus-glib (PTS, buildd, popcon) Reported by: Simon M ...
An attacker could send crafted input to applications using DBus-GLib and cause them to crash ...