Local Access Bypass in DBus-GLib Affecting Service Management Tools
CVE-2010-1172
Currently unrated
Key Information:
- Vendor
Freedesktop
- Status
- Vendor
- CVE Published:
- 20 August 2010
What is CVE-2010-1172?
DBus-GLib versions prior to a certain update are susceptible to a local access control bypass vulnerability. This occurs as the software does not properly enforce the access flag on exported GObject properties. As a result, unauthorized local users can manipulate properties associated with critical system services such as DeviceKit-Power, NetworkManager, and ModemManager. This flaw potentially leads to a Denial of Service condition as users modify key service configurations.