LOW
dbus: invalid fix for CVE-2008-3834
Published Apr 27, 2009
3.6
LOWCVSS 2.0
EPSS 1.32%
Description
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.
Affected products
No data.
OR
- ≤ 1.2.3
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.7
- 0.8
- 0.9
- 0.10
- 0.11
- 0.12
- 0.13
- 0.20
- 0.21
- 0.22
- 0.23
- 0.23.1
- 0.23.2
- 0.23.3
- 0.31
- 0.32
- 0.33
- 0.34
- 0.35
- 0.35.1
- 0.35.2
- 0.36
- 0.36.1
- 0.36.2
- 0.50
- 0.60
- 0.61
- 0.62
- 0.90
- 0.91
- 0.92
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0.2
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.4
- 1.1.20
- 1.2.1
No data.
Red Hat Enterprise Linux 5
dbus-0:1.1.2-12.el5_4.1
Fixed · RHSA-2010:0018
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | dbus-0:1.1.2-12.el5_4.1 | Fixed | RHSA-2010:0018 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (18)
- http://bugs.freedesktop.org/show_bug.cgi?id=17803 x_refsource_CONFIRMExploit
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRM
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/32127 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35810 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38794 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a x_refsource_CONFIRMPatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2009/04/16/13 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/31602 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2010/0528 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1189 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=496672 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50385 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1189
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10308 vdb-entrysignaturex_refsource_OVAL
- https://rhn.redhat.com/errata/RHSA-2010-0095.html vendor-advisoryx_refsource_REDHAT
- https://usn.ubuntu.com/799-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2009-1189
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 27, 2009
Updated Aug 7, 2024
Reserved Mar 31, 2009
Link CVE-2009-1189
CISA Vulnrichment
Updated n/a