Hide Forgot
A privilege escalation flaw was found in the way dbus-glib, the D-Bus add-on library to integrate the standard D-Bus library with the GLib thread abstraction and main loop, performed filtering of the message sender (message source subject), when the NameOwnerChanged signal was received. A local attacker could use this flaw to escalate their privileges. Relevant upstream patch: [1] http://cgit.freedesktop.org/dbus/dbus-glib/commit/?id=166978a09cf5edff4028e670b6074215a4c75eca References: [2] http://www.openwall.com/lists/oss-security/2013/02/15/10
Created dbus-glib tracking bugs for this issue Affects: fedora-all [bug 911714]
dbus-glib upstream bug report: https://bugs.freedesktop.org/show_bug.cgi?id=60916
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 5 Via RHSA-2013:0568 https://rhn.redhat.com/errata/RHSA-2013-0568.html