D-Bus Remote Signature Spoofing Vulnerability Affecting Freedesktop.org
CVE-2009-1189

Currently unrated

Key Information:

Status
Vendor
CVE Published:
27 April 2009

What is CVE-2009-1189?

A security flaw exists in the D-Bus system due to incorrect logic in the _dbus_validate_signature_with_reason function. This vulnerability permits remote attackers to create a bogus signature using a specially crafted key, undermining the integrity of the signing process. This flaw originated from a defective resolution to a prior issue (CVE-2008-3834), allowing exploitation in versions prior to 1.2.14.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.