Title : D-Bus Method Call Access Validation Security Policy Bypass Issue VUPEN ID : VUPEN/ADV-2008-0694 CVE ID : CVE-2008-0595
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2008-02-28
Technical Description
A vulnerability has been identified in D-Bus, which could be exploited by attackers to bypass security restrictions. This issue is caused by errors in the "bus_client_policy_check_can_send()" and "bus_client_policy_check_can_receive()" [bus/policy.c] functions when verifying whether or not a caller is allowed to access a method call, which could be exploited by malicious users with the ability to connect to a vulnerable daemon to execute certain method calls they should normally not have permission to access.