CVE-2008-0595: Medium severity red hat fedora vulnerability
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes sendinterface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0595?
CVE-2008-0595 has been classified as a medium severity vulnerability.
How do I fix CVE-2008-0595?
You can fix CVE-2008-0595 by upgrading D-Bus to version 1.0.3 or later, or ensure you are using a version within the 1.1.x series above 1.1.20.
Which systems are affected by CVE-2008-0595?
CVE-2008-0595 affects D-Bus versions prior to 1.0.3 and 1.1.x before 1.1.20 on various distributions including Fedora, Mandrake, and Red Hat Enterprise Linux.
What type of attack does CVE-2008-0595 facilitate?
CVE-2008-0595 allows local users to bypass intended access restrictions through method calls with a NULL interface.
Is there a patch available for CVE-2008-0595?
Yes, patches have been released for CVE-2008-0595 with the corresponding updates in the D-Bus versions mentioned.