Local Access Bypass in DBus-GLib Affecting Service Management Tools
CVE-2010-1172

Currently unrated

Key Information:

Status
Vendor
CVE Published:
20 August 2010

What is CVE-2010-1172?

DBus-GLib versions prior to a certain update are susceptible to a local access control bypass vulnerability. This occurs as the software does not properly enforce the access flag on exported GObject properties. As a result, unauthorized local users can manipulate properties associated with critical system services such as DeviceKit-Power, NetworkManager, and ModemManager. This flaw potentially leads to a Denial of Service condition as users modify key service configurations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.