CVE-2019-12749
Description
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofing because of symlink mishandling in the reference implementation of DBUS_COOKIE_SHA1 in the libdbus library. (This only affects the DBUS_COOKIE_SHA1 authentication mechanism.) A malicious client with write access to its own home directory could manipulate a ~/.dbus-keyrings symlink to cause a DBusServer with a different uid to read and write in unintended locations. In the worst case, this could result in the DBusServer reusing a cookie that is known to the malicious client, and treating that cookie as evidence that a subsequent client connection came from an attacker-chosen uid, allowing authentication bypass.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in IBM Security Guardium 10.5 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 10.6 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.2 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.3 | Windows |
| Multiple Vulnerabilities are affected in IBM Security Guardium 11.0 | Windows |
| simple interprocess messaging system (USN-1576-1) dbus_1.4.18-1ubuntu1.8_i386.deb | Linux |
| simple interprocess messaging system (USN-1576-1) dbus_1.4.18-1ubuntu1.8_amd64.deb | Linux |
| simple interprocess messaging system (USN-1576-1) libdbus-1-3_1.4.18-1ubuntu1.8_i386.deb | Linux |
| simple interprocess messaging system (USN-1576-1) libdbus-1-3_1.4.18-1ubuntu1.8_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.10.6-1ubuntu3.4_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.10.6-1ubuntu3.4_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.12.2-1ubuntu1.1_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.12.2-1ubuntu1.1_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.12.10-1ubuntu2.1_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.12.10-1ubuntu2.1_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.12.12-1ubuntu1.1_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) dbus_1.12.12-1ubuntu1.1_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.10.6-1ubuntu3.4_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.10.6-1ubuntu3.4_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.12.2-1ubuntu1.1_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.12.2-1ubuntu1.1_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.12.10-1ubuntu2.1_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.12.10-1ubuntu2.1_amd64.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.12.12-1ubuntu1.1_i386.deb | Linux |
| simple interprocess messaging system (USN-4015-1) libdbus-1-3_1.12.12-1ubuntu1.1_amd64.deb | Linux |
| dbus security update(DSA-4462-1) dbus_1.10.28-0+deb9u1_i386.deb | Linux |
| dbus security update(DSA-4462-1) dbus_1.10.28-0+deb9u1_amd64.deb | Linux |
| (RHSA-2019:1726) dbus security update dbus-1.2.24-11.el6_10.x86_64.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-devel-1.2.24-11.el6_10.i686.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-devel-1.2.24-11.el6_10.x86_64.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-doc-1.2.24-11.el6_10.noarch.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-libs-1.2.24-11.el6_10.i686.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-libs-1.2.24-11.el6_10.x86_64.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-x11-1.2.24-11.el6_10.i686.rpm | Linux |
| (RHSA-2019:1726) dbus security update dbus-x11-1.2.24-11.el6_10.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-1.8.22-29.17.12.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-debuginfo-1.8.22-29.17.12.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-debuginfo-32bit-1.8.22-29.17.12.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-debugsource-1.8.22-29.17.7.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-x11-1.8.22-29.17.12.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-x11-debuginfo-1.8.22-29.17.12.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) dbus-1-x11-debugsource-1.8.22-29.17.12.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) libdbus-1-3-1.8.22-29.17.7.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) libdbus-1-3-32bit-1.8.22-29.17.7.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) libdbus-1-3-debuginfo-1.8.22-29.17.7.x86_64.rpm | Linux |
| SUSE-SU-2019:2820-1(SUSE Linux Enterprise Desktop 12-SP4 ) libdbus-1-3-debuginfo-32bit-1.8.22-29.17.7.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-1.12.8-9.el8.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-common-1.12.8-9.el8.noarch.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-daemon-1.12.8-9.el8.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-debugsource-1.12.8-9.el8.i686.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-debugsource-1.12.8-9.el8.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-devel-1.12.8-9.el8.i686.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-devel-1.12.8-9.el8.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-libs-1.12.8-9.el8.i686.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-libs-1.12.8-9.el8.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-tools-1.12.8-9.el8.x86_64.rpm | Linux |
| (RHSA-2019:3707) dbus security update dbus-x11-1.12.8-9.el8.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) dbus-1-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) dbus-1-debuginfo-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) dbus-1-debugsource-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) dbus-1-x11-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) dbus-1-x11-debuginfo-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) dbus-1-x11-debugsource-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) libdbus-1-3-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) libdbus-1-3-32bit-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) libdbus-1-3-debuginfo-1.8.22-11.3.1.x86_64.rpm | Linux |
| SUSE-SU-2020:1672-1(SUSE Linux Enterprise Server 12-SP5 ) libdbus-1-3-debuginfo-32bit-1.8.22-11.3.1.x86_64.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-1.10.24-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-devel-1.10.24-15.el7.i686.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-devel-1.10.24-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-doc-1.10.24-15.el7.noarch.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-libs-1.10.24-15.el7.i686.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-libs-1.10.24-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-tests-1.10.24-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:4032) dbus security update dbus-x11-1.10.24-15.el7.x86_64.rpm | Linux |
| Dbus update (ELSA-2019-1726) dbus-1.2.24-11.0.1.el6_10.x86_64.rpm | Linux |
| Dbus-devel update (ELSA-2019-1726) dbus-devel-1.2.24-11.0.1.el6_10.x86_64.rpm | Linux |
| Dbus-libs update (ELSA-2019-1726) dbus-libs-1.2.24-11.0.1.el6_10.x86_64.rpm | Linux |
| Dbus-x11 update (ELSA-2019-1726) dbus-x11-1.2.24-11.0.1.el6_10.x86_64.rpm | Linux |
| Dbus-doc update (ELSA-2019-1726) dbus-doc-1.2.24-11.0.1.el6_10.noarch.rpm | Linux |
| Dbus update (ELSA-2019-1726) dbus-1.2.24-11.0.1.el6_10.i686.rpm | Linux |
| Dbus-devel update (ELSA-2019-1726) dbus-devel-1.2.24-11.0.1.el6_10.i686.rpm | Linux |
| Dbus-libs update (ELSA-2019-1726) dbus-libs-1.2.24-11.0.1.el6_10.i686.rpm | Linux |
| Dbus-x11 update (ELSA-2019-1726) dbus-x11-1.2.24-11.0.1.el6_10.i686.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-1.12.8-9.el8.x86_64.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-common-1.12.8-9.el8.noarch.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-daemon-1.12.8-9.el8.x86_64.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-devel-1.12.8-9.el8.i686.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-devel-1.12.8-9.el8.x86_64.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-libs-1.12.8-9.el8.i686.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-libs-1.12.8-9.el8.x86_64.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-tools-1.12.8-9.el8.x86_64.rpm | Linux |
| (CESA-2019:3707) dbus security update dbus-x11-1.12.8-9.el8.x86_64.rpm | Linux |
| (CESA-2020:4032) dbus security update dbus-1.10.24-15.el7.x86_64.rpm | Linux |
| (CESA-2020:4032) dbus security update dbus-devel-1.10.24-15.el7.x86_64.rpm | Linux |
| (CESA-2020:4032) dbus security update dbus-doc-1.10.24-15.el7.noarch.rpm | Linux |
| (CESA-2020:4032) dbus security update dbus-libs-1.10.24-15.el7.x86_64.rpm | Linux |
| (CESA-2020:4032) dbus security update dbus-tests-1.10.24-15.el7.x86_64.rpm | Linux |
| (CESA-2020:4032) dbus security update dbus-x11-1.10.24-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:4032)Moderate: security update dbus-debuginfo-1.10.24-15.el7.i686.rpm | Linux |
| (RHSA-2020:4032)Moderate: security update dbus-debuginfo-1.10.24-15.el7.x86_64.rpm | Linux |
| Improper Link Resolution Before File Access (Link Following) Vulnerability (CVE-2019-12749) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234