CVE-2010-1172

EUVD-2010-1202
DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
freedesktopdbus-glib
0.73
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
dbus-glib
bookworm
0.112-3
fixed
bullseye
0.110-6
fixed
lenny
no-dsa
sid
0.112-3
fixed
trixie
0.112-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
dbus-glib
dapper
dne
hardy
Fixed 0.74-2ubuntu0.1
released
jaunty
ignored
karmic
ignored
lucid
Fixed 0.84-1ubuntu0.2
released
maverick
not-affected
natty
not-affected
Common Weakness Enumeration
References