CVE-2009-1189

The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key.  NOTE: this is due to an incorrect fix for CVE-2008-3834.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
freedesktopdbus
𝑥
≤ 1.2.3
freedesktopdbus
0.1
freedesktopdbus
0.2
freedesktopdbus
0.3
freedesktopdbus
0.4
freedesktopdbus
0.5
freedesktopdbus
0.6
freedesktopdbus
0.7
freedesktopdbus
0.8
freedesktopdbus
0.9
freedesktopdbus
0.10
freedesktopdbus
0.11
freedesktopdbus
0.12
freedesktopdbus
0.13
freedesktopdbus
0.20
freedesktopdbus
0.21
freedesktopdbus
0.22
freedesktopdbus
0.23
freedesktopdbus
0.23.1
freedesktopdbus
0.23.2
freedesktopdbus
0.23.3
freedesktopdbus
0.31
freedesktopdbus
0.32
freedesktopdbus
0.33
freedesktopdbus
0.34
freedesktopdbus
0.35
freedesktopdbus
0.35.1
freedesktopdbus
0.35.2
freedesktopdbus
0.36
freedesktopdbus
0.36.1
freedesktopdbus
0.36.2
freedesktopdbus
0.50
freedesktopdbus
0.60
freedesktopdbus
0.61
freedesktopdbus
0.62
freedesktopdbus
0.90
freedesktopdbus
0.91
freedesktopdbus
0.92
freedesktopdbus
1.0
freedesktopdbus
1.0:rc1
freedesktopdbus
1.0:rc2
freedesktopdbus
1.0:rc3
freedesktopdbus
1.0.2
freedesktopdbus
1.1.0
freedesktopdbus
1.1.1
freedesktopdbus
1.1.2
freedesktopdbus
1.1.4
freedesktopdbus
1.1.20
freedesktopdbus
1.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dbus
bullseye
1.12.28-0+deb11u1
fixed
bullseye (security)
1.12.24-0+deb11u1
fixed
bookworm
1.14.10-1~deb12u1
fixed
sid
1.14.10-6
fixed
trixie
1.14.10-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dbus
jaunty
Fixed 1.2.12-0ubuntu2.1
released
intrepid
Fixed 1.2.4-0ubuntu1.1
released
hardy
Fixed 1.1.20-1ubuntu3.3
released
dapper
Fixed 0.60-6ubuntu8.4
released
References