CVE-2010-1172

DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
freedesktopdbus-glib
0.73
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dbus-glib
bullseye
0.110-6
fixed
lenny
no-dsa
sid
0.112-3
fixed
trixie
0.112-3
fixed
bookworm
0.112-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dbus-glib
natty
not-affected
maverick
not-affected
lucid
Fixed 0.84-1ubuntu0.2
released
karmic
ignored
jaunty
ignored
hardy
Fixed 0.74-2ubuntu0.1
released
dapper
dne
Common Weakness Enumeration
References