CVE-2013-0292

Publication date 15 February 2013

Last updated 24 July 2024


Ubuntu priority

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

Read the notes from the security team

Status

Package Ubuntu Release Status
dbus-glib 12.10 quantal
Fixed 0.100-1ubuntu0.1
12.04 LTS precise
Fixed 0.98-1ubuntu1.1
11.10 oneiric
Fixed 0.94-4ubuntu0.1
10.04 LTS lucid
Fixed 0.84-1ubuntu0.3
8.04 LTS hardy Ignored end of life

Notes


seth-arnold

local privilege escalation demonstrated with pam_fprintd dbus-glib is deprecated

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
dbus-glib

References

Related Ubuntu Security Notices (USN)

    • USN-1753-1
    • DBus-GLib vulnerability
    • 27 February 2013

Other references